krisss
Topic Starter
Hi,
I am having these two viruses in my system and having a hard time removing them.
The below 2 viruses are picked up by spybot but failed to remove them by saying "c:\windows\system32\drivers\etc Acess is denied"
1. Fraud.WindowProtectionSuite
2. Microsoft.Window.RedirectHosts.
I did look at the same issue in the forum.
I downloaded combofix and ran the same, below is the log. Any input would be of great help.
ComboFix 09-11-25.05 - kveerappa 11/26/2009 8:54.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3582.2672 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}\chrome.manifest
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}\chrome\content\_cfg.js
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}\chrome\content\overlay.xul
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}\install.rdf
c:\recycler\S-1-5-21-1148212273-670532697-2008175689-500
c:\recycler\S-1-5-21-1547161642-746137067-839522115-500
c:\recycler\S-1-5-21-3436562845-356841921-1497333993-500
c:\recycler\S-1-5-21-3896539928-1599609400-794918191-500
c:\recycler\S-1-5-21-884609397-1866408068-2337108139-500
c:\windows\system32\Cache
c:\windows\system32\flags.ini
c:\windows\system32\mscert.dll
c:\windows\system32\rdolib.dll
c:\windows\system32\uses32.dat
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
c:\windows\Tasks\startAltiris_test.bat
c:\windows\TEMP\logishrd\LVPrcInj01.dll
Infected copy of c:\windows\system32\drivers\ntfs.sys was found and disinfected
Restored copy from - c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys
.
((((((((((((((((((((((((( Files Created from 2009-10-26 to 2009-11-26 )))))))))))))))))))))))))))))))
.
2009-11-26 05:42 . 2009-07-28 20:33 55656 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-26 05:42 . 2009-03-30 14:33 96104 —-a-w- c:\windows\system32\drivers\avipbb.sys
2009-11-26 05:42 . 2009-02-13 16:29 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-11-26 05:42 . 2009-02-13 16:17 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2009-11-26 05:42 . 2009-11-26 05:42 ——– d—–w- c:\program files\Avira
2009-11-26 05:42 . 2009-11-26 05:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2009-11-26 04:57 . 2009-11-26 05:38 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-11-26 04:53 . 2009-11-10 15:28 149456 —-a-w- c:\windows\SGDetectionTool.dll
2009-11-26 04:53 . 2009-11-10 15:26 767952 —-a-w- c:\windows\BDTSupport.dll
2009-11-26 04:53 . 2009-10-28 06:36 1152444 —-a-w- c:\windows\UDB.zip
2009-11-26 04:53 . 2008-11-26 17:08 131 —-a-w- c:\windows\IDB.zip
2009-11-26 04:53 . 2009-11-10 15:28 165840 —-a-w- c:\windows\PCTBDRes.dll
2009-11-26 04:53 . 2009-11-10 15:28 1640400 —-a-w- c:\windows\PCTBDCore.dll
2009-11-26 04:50 . 2009-10-30 16:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-11-26 04:50 . 2009-11-09 16:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-11-26 04:50 . 2009-10-06 21:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-11-26 04:50 . 2009-09-03 14:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-11-26 04:50 . 2009-11-26 04:53 ——– d—–w- c:\program files\Spyware Doctor
2009-11-26 04:50 . 2009-11-26 04:50 ——– d—–w- c:\program files\Common Files\PC Tools
2009-11-26 04:50 . 2009-11-26 04:50 ——– d—–w- c:\documents and settings\kveerappa\Application Data\PC Tools
2009-11-26 04:50 . 2009-11-26 04:50 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-11-26 04:11 . 2009-11-26 04:11 ——– d—–w- c:\documents and settings\kveerappa\Local Settings\Application Data\Threat Expert
2009-11-26 03:56 . 2009-11-26 14:15 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-25 20:01 . 2009-11-25 20:01 ——– d—–w- c:\documents and settings\athena\Local Settings\Application Data\Mozilla
2009-11-25 19:47 . 2009-11-25 19:47 ——– d—–w- c:\documents and settings\athena\Local Settings\Application Data\Cisco
2009-11-25 19:40 . 2009-11-25 19:40 ——– d-sh–w- c:\documents and settings\athena\PrivacIE
2009-11-25 19:40 . 2009-11-25 19:40 ——– d—–w- c:\documents and settings\athena\Local Settings\Application Data\Google
2009-11-25 19:39 . 2009-11-25 19:39 ——– d—–w- c:\documents and settings\athena\Application Data\Malwarebytes
2009-11-25 19:38 . 2009-11-25 19:38 ——– d-sh–w- c:\documents and settings\athena\IETldCache
2009-11-25 18:47 . 2009-11-25 18:47 ——– d—–w- c:\windows\DWRCS Uploads
2009-11-25 17:58 . 2009-11-25 17:58 51636 —ha-w- c:\windows\system32\mlfcache.dat
2009-11-25 03:54 . 2009-11-25 03:54 ——– d—–w- c:\documents and settings\kveerappa\Application Data\Malwarebytes
2009-11-25 03:54 . 2009-11-25 03:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-25 03:52 . 2009-11-25 03:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-11-25 01:42 . 2009-11-25 18:14 120 —-a-w- c:\windows\Rcikumuqoboxeb.dat
2009-11-25 01:42 . 2009-11-25 14:12 0 —-a-w- c:\windows\Wvopaqoxisigih.bin
2009-11-25 01:09 . 2009-11-25 01:09 ——– d-sh–w- c:\documents and settings\LocalService\PrivacIE
2009-11-23 19:16 . 2009-11-23 19:16 ——– d—–w- c:\documents and settings\kveerappa\691509.tmp
2009-11-23 18:53 . 2009-11-23 18:53 ——– d—–w- c:\documents and settings\kveerappa\808405.tmp
2009-11-11 05:28 . 2009-11-11 05:28 247280 —-a-w- c:\documents and settings\kveerappa\Application Data\Mozilla\plugins\npgoogletalk.dll
2009-11-05 23:25 . 2009-11-05 23:25 593920 —-a-w- c:\documents and settings\kveerappa\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv305hw-0910190-0-main.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-26 05:33 . 2007-10-19 12:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-26 02:57 . 2007-10-18 19:25 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-11-26 02:57 . 2007-10-18 19:26 ——– d—–w- c:\program files\Symantec
2009-11-26 02:50 . 2007-10-18 19:25 ——– d—–w- c:\program files\Symantec AntiVirus
2009-11-26 02:49 . 2007-10-18 19:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-11-25 22:15 . 2008-08-27 08:35 ——– d—–w- c:\documents and settings\kveerappa\Application Data\Yahoo!
2009-11-25 19:39 . 2007-10-18 21:18 102630 —-a-w- c:\windows\system32\nvModes.dat
2009-11-20 17:19 . 2008-08-18 04:25 ——– d—–w- c:\documents and settings\kveerappa\Application Data\U3
2009-10-18 12:32 . 2009-10-18 12:32 ——– d—–w- c:\program files\MSXML 6.0
2009-09-28 13:03 . 2009-09-28 13:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Cisco
2009-09-28 13:03 . 2009-09-28 13:03 ——– d—–w- c:\program files\Cisco
2009-09-04 20:45 . 2004-08-04 07:56 58880 —-a-w- c:\windows\system32\msasn1.dll
2009-09-01 23:01 . 2009-09-01 23:01 127872 —-a-w- c:\documents and settings\kveerappa\Application Data\Move Networks\uninstall.exe
2009-09-01 23:01 . 2009-06-16 06:35 4183416 —-a-w- c:\documents and settings\kveerappa\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-08-29 08:08 . 2004-08-04 07:56 916480 —-a-w- c:\windows\system32\wininet.dll
2005-11-15 10:02 . 2005-11-15 10:02 3638 —-a-r- c:\program files\Common Files\Altiris_Icon.ico
2003-02-22 23:24 . 2003-02-22 23:24 107 —-a-w- c:\program files\zMarker.txt
2009-02-10 12:01 . 2007-10-18 22:05 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-02-10 12:01 . 2007-10-18 22:05 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-02-10 12:01 . 2007-10-18 22:05 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-02-10 12:01 . 2007-10-18 22:05 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-02-10 12:01 . 2007-10-18 22:05 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2008-09-10 13:22 . 2008-09-10 13:22 10856 –sha-w- c:\windows\system32\KGyGaAvL.sys
.
——- Sigcheck ——-
[-] 2007-09-27 . 6E266AAF4168B3569A330C61AB01F6B4 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\P4EXPCheckoutOverlay]
@="{80E008A4-EAE7-4867-AEB0-1A245F070F25}"
[HKEY_CLASSES_ROOT\CLSID\{80E008A4-EAE7-4867-AEB0-1A245F070F25}]
2008-02-06 23:17 557056 —-a-r- c:\devtools\Perforce\p4exp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\P4EXPSyncdOverlay]
@="{ADF262C1-E8FE-49BE-AD63-F77CD4A6CCD9}"
[HKEY_CLASSES_ROOT\CLSID\{ADF262C1-E8FE-49BE-AD63-F77CD4A6CCD9}]
2008-02-06 23:17 557056 —-a-r- c:\devtools\Perforce\p4exp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\P4EXPUpdateOverlay]
@="{C550CDA2-37D7-4838-A9D7-65ECB1EB5AB2}"
[HKEY_CLASSES_ROOT\CLSID\{C550CDA2-37D7-4838-A9D7-65ECB1EB5AB2}]
2008-02-06 23:17 557056 —-a-r- c:\devtools\Perforce\p4exp.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-26 4351216]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-22 39408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SgeEcView"="c:\program files\Utimaco\SafeGuard Easy\Ecview.exe" [2007-09-05 24576]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-28 81920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]
"EdWizard"="c:\program files\Utimaco\SafeGuard Easy\EdWizard.exe" [2007-09-05 245760]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-07-20 1228800]
"AeXAgentLogon"="c:\program files\Altiris\Altiris Agent\AeXAgentActivate.exe" [2009-04-30 153416]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"DameWare MRC Agent"="c:\windows\system32\DWRCST.exe" [2009-02-04 78848]
"NVHotkey"="nvHotkey.dll" - c:\windows\system32\nvhotkey.dll [2007-04-28 67584]
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NotLog]
2002-01-22 09:58 110592 —-a-w- c:\windows\system32\SGLogEx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SGLogNotification]
2005-03-31 05:57 69632 —-a-w- c:\windows\system32\SGLogNotification.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor Apache Servers.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
backup=c:\windows\pss\Monitor Apache Servers.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\devtools\\MKS\\bin\\secshd.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\devtools\\jre1.5.0_14\\bin\\javaw.exe"=
"d:\\devtools\\bea81\\jdk142_05\\bin\\java.exe"=
"c:\\devtools\\jdk1.4.2_02\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\kveerappa\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\kveerappa\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\NX Client for Windows\\nxclient.exe"=
"c:\\Program Files\\NX Client for Windows\\bin\\nxssh.exe"=
"d:\\devtools\\bea101\\jdk150_11\\jre\\bin\\java.exe"=
"d:\\Ariba\\Demo9r1\\Upstream\\Server\\3rdParty\\jre\\NT\\1.5.0\\bin\\java.exe"=
"c:\\devtools\\jdk1.5.0_14\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\devtools\\bea101\\jdk150_11\\bin\\java.exe"=
"d:\\Ariba\\JPMC9r1\\Downstream\\Server\\3rdParty\\jre\\NT\\1.5.0\\bin\\java.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Documents and Settings\\kveerappa\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6129:TCP"= 6129:TCP:Dameware
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"2015:UDP"= 2015:UDP:Windows Media Format SDK (IEXPLORE.EXE)
"2014:UDP"= 2014:UDP:Windows Media Format SDK (IEXPLORE.EXE)
"2017:UDP"= 2017:UDP:Windows Media Format SDK (IEXPLORE.EXE)
R0 AES-256;AES-256;c:\windows\system32\drivers\AES256.sys [9/5/2007 3:20 AM 19712]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [11/25/2009 11:50 PM 207792]
R0 SgeFlt;SgeFlt;c:\windows\system32\drivers\SGEFLT.sys [9/5/2007 3:20 AM 62720]
R1 FSLX;FSLX;c:\windows\system32\drivers\fslx.sys [7/21/2008 12:01 AM 192256]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [11/26/2009 12:42 AM 108289]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [11/25/2009 11:53 PM 112592]
R2 MKSAUTH;MKSAUTH;c:\windows\system32\mksauth.exe [7/25/2007 12:07 PM 94168]
R2 MKSRlogind;MKS Rlogind;c:\devtools\MKS\bin\rlogind.exe [6/7/2007 12:41 PM 69848]
R2 MKSSecureSH;MKS Secure Shell Service;c:\devtools\MKS\bin\secshd.exe [7/16/2007 6:11 PM 360408]
R2 NuTCRACKERService;NuTCRACKER Service;c:\windows\system32\nutsrv4.exe [7/20/2007 3:31 PM 315424]
R2 OracleServiceARIBA1;OracleServiceARIBA1;c:\devtools\ora10.2.0\bin\ORACLE.EXE ARIBA1 –> c:\devtools\ora10.2.0\bin\ORACLE.EXE ARIBA1 [?]
R2 REXECD;REXECD;c:\devtools\MKS\mksnt\rexecd.exe [7/25/2007 12:10 PM 102360]
R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [6/17/2009 3:17 PM 434864]
R3 DwMirror;DwMirror;c:\windows\system32\drivers\DamewareMini.sys [2/7/2007 4:30 PM 3712]
S2 OracleDBConsoleARIBA1;OracleDBConsoleARIBA1;c:\devtools\ora10.2.0\BIN\nmesrvc.exe [3/24/2009 10:11 PM 24064]
S2 OracleOraDb10g_home1TNSListener;OracleOraDb10g_home1TNSListener;c:\devtools\ora10.2.0\BIN\TNSLSNR –> c:\devtools\ora10.2.0\BIN\TNSLSNR [?]
S2 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" –> c:\program files\Symantec AntiVirus\SavRoam.exe [?]
S3 CSVirtA;Cisco Systems SSL VPN Adapter;c:\windows\system32\drivers\CSVirtA.sys [3/3/2009 11:20 PM 22136]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [?]
S3 OracleOraHome92Agent;OracleOraHome92Agent;d:\devtools\oracle\ora92\bin\agntsrvc.exe [4/26/2002 6:59 AM 28944]
S3 OracleOraHome92HTTPServer;OracleOraHome92HTTPServer;d:\devtools\oracle\ora92\Apache\Apache\Apache.exe [4/18/2002 11:32 AM 4096]
S3 OracleOraHome92SNMPPeerEncapsulator;OracleOraHome92SNMPPeerEncapsulator;d:\devtools\oracle\ora92\bin\encsvc.exe [2/12/2002 9:53 PM 187392]
S3 OracleOraHome92SNMPPeerMasterAgent;OracleOraHome92SNMPPeerMasterAgent;d:\devtools\oracle\ora92\bin\agntsvc.exe [2/12/2002 9:53 PM 254464]
S3 OracleServiceARIBA;OracleServiceARIBA;d:\devtools\oracle\ora92\bin\ORACLE.EXE ARIBA –> d:\devtools\oracle\ora92\bin\ORACLE.EXE ARIBA [?]
S3 Tomcat6;Apache Tomcat;d:\kris\ProgramFiles\Tomcat 6.0\bin\tomcat6.exe [1/28/2008 5:39 PM 57344]
S4 MKSTelnetd;MKS Telnetd;c:\windows\system32\telnetd.exe [6/7/2007 12:40 PM 114904]
S4 OracleJobSchedulerARIBA1;OracleJobSchedulerARIBA1;c:\devtools\ora10.2.0\Bin\extjob.exe ARIBA1 –> c:\devtools\ora10.2.0\Bin\extjob.exe ARIBA1 [?]
S4 RSHD;RSHD;c:\devtools\MKS\mksnt\rshd.exe [7/25/2007 12:10 PM 114648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
vvdsvc REG_MULTI_SZ vvdsvc
.
Contents of the 'Scheduled Tasks' folder
2009-11-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1604221776-839522115-64179Core.job
- c:\documents and settings\kveerappa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 08:31]
2009-11-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1604221776-839522115-64179UA.job
- c:\documents and settings\kveerappa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 08:31]
2009-11-26 c:\windows\Tasks\User_Feed_Synchronization-{289DB8EB-F584-4124-8768-93085DB71593}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://web.ariba.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: %SystemRoot%\system32\nutafun4.dll
TCP: {7C93048F-1CEF-4378-819F-0E6BDDA55A30} = 10.1.1.10,10.1.1.11
DPF: {25C89FF5-4A85-4183-81F2-6C0C1B514297} - hxxps://crm.ariba.com/hi/18382/applets/SiebelAx_HI_Client.cab
DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} - hxxps://snv-acdcasa/CACHE/stc/1/binaries/stcweb.cab
DPF: {31C799C0-32B1-4EFE-87FC-CF506C14338B} - hxxps://crm.ariba.com/hi/18382/applets/SiebelAx_OutBound_mail.cab
DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} - hxxps://rapgh.ariba.com/CACHE/stc/1/binaries/vpnweb.cab
DPF: {61803B6E-0994-4C05-AC45-1FE2EEDADECB} - hxxps://zinfandel.ariba.com/DemoACM/ariba/resource/en_US/lib/winXP/clientautomation.cab
DPF: {8AFC9162-C354-4022-9E7E-ED4D41A9A284} - hxxp://kveerappa1.ariba.com/DemoAribaASM/ariba/resource/en_US/lib/clientautomation.cab
DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} - hxxps://crm.ariba.com/hi/18382/applets/SiebelAx_Desktop_Integration.cab
DPF: {FDF527BA-DDDA-11D3-AA82-006094EB09CB} - hxxp://help/aspnet_client/Altiris_AppWeaver/6_0_sp3/lib/AeXClipboard.CAB
FF - ProfilePath - c:\documents and settings\kveerappa\Application Data\Mozilla\Firefox\Profiles\3jr8cvzb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p;=
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p;=
FF - prefs.js: network.proxy.ftp - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.gopher - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.http - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.socks - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.ssl - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.type - 2
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
ShellIconOverlayIdentifiers-{ba930330-a721-11d3-a7b9-00500464ee16} - Sgedrse.Dll
ShellIconOverlayIdentifiers-{2030D939-54A7-4fea-9B06-49EA77EFC87F} - Sgedrse.Dll
HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
AddRemove-Broadcom 802.11b Network Adapter - c:\program files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe verbose
AddRemove-e84c95559d72a4b073d4840a41180d31 - d:\devtools\Tibco\_uninst\uninstallTibco.exe
AddRemove-NVIDIA Drivers - c:\windows\system32\nvudisp.exe UninstallGUI
AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-{D1DB41B3-0415-4D96-B53B-4B02B9AAD23A}-Visible - c:\documents and settings\zeus\Local Settings\Application Data\{D1DB41B3-0415-4D96-B53B-4B02B9AAD23A}\setup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-26 09:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OracleOraDb10g_home1TNSListener]
"ImagePath"="c:\devtools\ora10.2.0\BIN\TNSLSNR "
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OracleOraHome92PagingServer]
"ImagePath"="d:\devtools\oracle\ora92/bin/pagntsrv.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OracleOraHome92TNSListener]
"ImagePath"="d:\devtools\oracle\ora92\BIN\TNSLSNR "
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1744)
c:\windows\system32\WININET.dll
c:\windows\system32\SGLogEx.dll
c:\windows\system32\SGLogNotification.dll
c:\windows\system32\GetUserSid.dll
- - - - - - - > 'lsass.exe'(1808)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(5236)
c:\windows\system32\WININET.dll
c:\program files\Utimaco\SafeGuard Easy\SgMsgBhk.dll
c:\devtools\Perforce\p4exp.dll
c:\program files\Utimaco\SafeGuard Easy\SgeDrse.dll
c:\program files\Utimaco\SafeGuard Easy\SgeUtil.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\windows\system32\ConnAPI.DLL
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\windows\system32\CDRTC.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\program files\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Cisco Systems\SSL VPN Client\agent.exe
c:\windows\System32\bcmwltry.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Altiris\Altiris Agent\AeXNSAgent.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
d:\devtools\Apache Group\Apache2\bin\Apache.exe
d:\devtools\Apache Group\Apache2\bin\Apache.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\windows\system32\DWRCS.EXE
c:\program files\Dell\OpenManage\Client\Iap.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\MySQL\MySQL Server 5.1\bin\mysqld.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\windows\system32\nvsvc32.exe
d:\devtools\oracle\ora92\bin\omtsreco.exe
c:\devtools\ora10.2.0\bin\isqlplussvc.exe
c:\devtools\ora10.2.0\bin\ORACLE.EXE
c:\program files\Utimaco\SafeGuard Easy\SgeCtl.exe
c:\windows\system32\SgLogPlayer.exe
c:\windows\system32\StacSV.exe
c:\program files\RealVNC\VNC4\WinVNC4.exe
c:\program files\Utimaco\SafeGuard Easy\WksCfgSrv.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
c:\program files\Altiris\Altiris Agent\AeXAgentUIHost.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-11-26 09:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-26 14:24
Pre-Run: 20,016,668,672 bytes free
Post-Run: 19,984,228,352 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 00779E1F90B3FA4A99686950E5162EE2
I am having these two viruses in my system and having a hard time removing them.
The below 2 viruses are picked up by spybot but failed to remove them by saying "c:\windows\system32\drivers\etc Acess is denied"
1. Fraud.WindowProtectionSuite
2. Microsoft.Window.RedirectHosts.
I did look at the same issue in the forum.
I downloaded combofix and ran the same, below is the log. Any input would be of great help.
ComboFix 09-11-25.05 - kveerappa 11/26/2009 8:54.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3582.2672 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}\chrome.manifest
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}\chrome\content\_cfg.js
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}\chrome\content\overlay.xul
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}\install.rdf
c:\recycler\S-1-5-21-1148212273-670532697-2008175689-500
c:\recycler\S-1-5-21-1547161642-746137067-839522115-500
c:\recycler\S-1-5-21-3436562845-356841921-1497333993-500
c:\recycler\S-1-5-21-3896539928-1599609400-794918191-500
c:\recycler\S-1-5-21-884609397-1866408068-2337108139-500
c:\windows\system32\Cache
c:\windows\system32\flags.ini
c:\windows\system32\mscert.dll
c:\windows\system32\rdolib.dll
c:\windows\system32\uses32.dat
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
c:\windows\Tasks\startAltiris_test.bat
c:\windows\TEMP\logishrd\LVPrcInj01.dll
Infected copy of c:\windows\system32\drivers\ntfs.sys was found and disinfected
Restored copy from - c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys
.
((((((((((((((((((((((((( Files Created from 2009-10-26 to 2009-11-26 )))))))))))))))))))))))))))))))
.
2009-11-26 05:42 . 2009-07-28 20:33 55656 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-26 05:42 . 2009-03-30 14:33 96104 —-a-w- c:\windows\system32\drivers\avipbb.sys
2009-11-26 05:42 . 2009-02-13 16:29 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-11-26 05:42 . 2009-02-13 16:17 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2009-11-26 05:42 . 2009-11-26 05:42 ——– d—–w- c:\program files\Avira
2009-11-26 05:42 . 2009-11-26 05:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2009-11-26 04:57 . 2009-11-26 05:38 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-11-26 04:53 . 2009-11-10 15:28 149456 —-a-w- c:\windows\SGDetectionTool.dll
2009-11-26 04:53 . 2009-11-10 15:26 767952 —-a-w- c:\windows\BDTSupport.dll
2009-11-26 04:53 . 2009-10-28 06:36 1152444 —-a-w- c:\windows\UDB.zip
2009-11-26 04:53 . 2008-11-26 17:08 131 —-a-w- c:\windows\IDB.zip
2009-11-26 04:53 . 2009-11-10 15:28 165840 —-a-w- c:\windows\PCTBDRes.dll
2009-11-26 04:53 . 2009-11-10 15:28 1640400 —-a-w- c:\windows\PCTBDCore.dll
2009-11-26 04:50 . 2009-10-30 16:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-11-26 04:50 . 2009-11-09 16:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-11-26 04:50 . 2009-10-06 21:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-11-26 04:50 . 2009-09-03 14:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-11-26 04:50 . 2009-11-26 04:53 ——– d—–w- c:\program files\Spyware Doctor
2009-11-26 04:50 . 2009-11-26 04:50 ——– d—–w- c:\program files\Common Files\PC Tools
2009-11-26 04:50 . 2009-11-26 04:50 ——– d—–w- c:\documents and settings\kveerappa\Application Data\PC Tools
2009-11-26 04:50 . 2009-11-26 04:50 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-11-26 04:11 . 2009-11-26 04:11 ——– d—–w- c:\documents and settings\kveerappa\Local Settings\Application Data\Threat Expert
2009-11-26 03:56 . 2009-11-26 14:15 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-25 20:01 . 2009-11-25 20:01 ——– d—–w- c:\documents and settings\athena\Local Settings\Application Data\Mozilla
2009-11-25 19:47 . 2009-11-25 19:47 ——– d—–w- c:\documents and settings\athena\Local Settings\Application Data\Cisco
2009-11-25 19:40 . 2009-11-25 19:40 ——– d-sh–w- c:\documents and settings\athena\PrivacIE
2009-11-25 19:40 . 2009-11-25 19:40 ——– d—–w- c:\documents and settings\athena\Local Settings\Application Data\Google
2009-11-25 19:39 . 2009-11-25 19:39 ——– d—–w- c:\documents and settings\athena\Application Data\Malwarebytes
2009-11-25 19:38 . 2009-11-25 19:38 ——– d-sh–w- c:\documents and settings\athena\IETldCache
2009-11-25 18:47 . 2009-11-25 18:47 ——– d—–w- c:\windows\DWRCS Uploads
2009-11-25 17:58 . 2009-11-25 17:58 51636 —ha-w- c:\windows\system32\mlfcache.dat
2009-11-25 03:54 . 2009-11-25 03:54 ——– d—–w- c:\documents and settings\kveerappa\Application Data\Malwarebytes
2009-11-25 03:54 . 2009-11-25 03:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-25 03:52 . 2009-11-25 03:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-11-25 01:42 . 2009-11-25 18:14 120 —-a-w- c:\windows\Rcikumuqoboxeb.dat
2009-11-25 01:42 . 2009-11-25 14:12 0 —-a-w- c:\windows\Wvopaqoxisigih.bin
2009-11-25 01:09 . 2009-11-25 01:09 ——– d-sh–w- c:\documents and settings\LocalService\PrivacIE
2009-11-23 19:16 . 2009-11-23 19:16 ——– d—–w- c:\documents and settings\kveerappa\691509.tmp
2009-11-23 18:53 . 2009-11-23 18:53 ——– d—–w- c:\documents and settings\kveerappa\808405.tmp
2009-11-11 05:28 . 2009-11-11 05:28 247280 —-a-w- c:\documents and settings\kveerappa\Application Data\Mozilla\plugins\npgoogletalk.dll
2009-11-05 23:25 . 2009-11-05 23:25 593920 —-a-w- c:\documents and settings\kveerappa\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv305hw-0910190-0-main.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-26 05:33 . 2007-10-19 12:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-26 02:57 . 2007-10-18 19:25 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-11-26 02:57 . 2007-10-18 19:26 ——– d—–w- c:\program files\Symantec
2009-11-26 02:50 . 2007-10-18 19:25 ——– d—–w- c:\program files\Symantec AntiVirus
2009-11-26 02:49 . 2007-10-18 19:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-11-25 22:15 . 2008-08-27 08:35 ——– d—–w- c:\documents and settings\kveerappa\Application Data\Yahoo!
2009-11-25 19:39 . 2007-10-18 21:18 102630 —-a-w- c:\windows\system32\nvModes.dat
2009-11-20 17:19 . 2008-08-18 04:25 ——– d—–w- c:\documents and settings\kveerappa\Application Data\U3
2009-10-18 12:32 . 2009-10-18 12:32 ——– d—–w- c:\program files\MSXML 6.0
2009-09-28 13:03 . 2009-09-28 13:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Cisco
2009-09-28 13:03 . 2009-09-28 13:03 ——– d—–w- c:\program files\Cisco
2009-09-04 20:45 . 2004-08-04 07:56 58880 —-a-w- c:\windows\system32\msasn1.dll
2009-09-01 23:01 . 2009-09-01 23:01 127872 —-a-w- c:\documents and settings\kveerappa\Application Data\Move Networks\uninstall.exe
2009-09-01 23:01 . 2009-06-16 06:35 4183416 —-a-w- c:\documents and settings\kveerappa\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-08-29 08:08 . 2004-08-04 07:56 916480 —-a-w- c:\windows\system32\wininet.dll
2005-11-15 10:02 . 2005-11-15 10:02 3638 —-a-r- c:\program files\Common Files\Altiris_Icon.ico
2003-02-22 23:24 . 2003-02-22 23:24 107 —-a-w- c:\program files\zMarker.txt
2009-02-10 12:01 . 2007-10-18 22:05 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-02-10 12:01 . 2007-10-18 22:05 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-02-10 12:01 . 2007-10-18 22:05 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-02-10 12:01 . 2007-10-18 22:05 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-02-10 12:01 . 2007-10-18 22:05 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2008-09-10 13:22 . 2008-09-10 13:22 10856 –sha-w- c:\windows\system32\KGyGaAvL.sys
.
——- Sigcheck ——-
[-] 2007-09-27 . 6E266AAF4168B3569A330C61AB01F6B4 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\P4EXPCheckoutOverlay]
@="{80E008A4-EAE7-4867-AEB0-1A245F070F25}"
[HKEY_CLASSES_ROOT\CLSID\{80E008A4-EAE7-4867-AEB0-1A245F070F25}]
2008-02-06 23:17 557056 —-a-r- c:\devtools\Perforce\p4exp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\P4EXPSyncdOverlay]
@="{ADF262C1-E8FE-49BE-AD63-F77CD4A6CCD9}"
[HKEY_CLASSES_ROOT\CLSID\{ADF262C1-E8FE-49BE-AD63-F77CD4A6CCD9}]
2008-02-06 23:17 557056 —-a-r- c:\devtools\Perforce\p4exp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\P4EXPUpdateOverlay]
@="{C550CDA2-37D7-4838-A9D7-65ECB1EB5AB2}"
[HKEY_CLASSES_ROOT\CLSID\{C550CDA2-37D7-4838-A9D7-65ECB1EB5AB2}]
2008-02-06 23:17 557056 —-a-r- c:\devtools\Perforce\p4exp.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-26 4351216]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-22 39408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SgeEcView"="c:\program files\Utimaco\SafeGuard Easy\Ecview.exe" [2007-09-05 24576]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-28 81920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]
"EdWizard"="c:\program files\Utimaco\SafeGuard Easy\EdWizard.exe" [2007-09-05 245760]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-07-20 1228800]
"AeXAgentLogon"="c:\program files\Altiris\Altiris Agent\AeXAgentActivate.exe" [2009-04-30 153416]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"DameWare MRC Agent"="c:\windows\system32\DWRCST.exe" [2009-02-04 78848]
"NVHotkey"="nvHotkey.dll" - c:\windows\system32\nvhotkey.dll [2007-04-28 67584]
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NotLog]
2002-01-22 09:58 110592 —-a-w- c:\windows\system32\SGLogEx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SGLogNotification]
2005-03-31 05:57 69632 —-a-w- c:\windows\system32\SGLogNotification.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor Apache Servers.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
backup=c:\windows\pss\Monitor Apache Servers.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\devtools\\MKS\\bin\\secshd.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\devtools\\jre1.5.0_14\\bin\\javaw.exe"=
"d:\\devtools\\bea81\\jdk142_05\\bin\\java.exe"=
"c:\\devtools\\jdk1.4.2_02\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\kveerappa\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\kveerappa\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\NX Client for Windows\\nxclient.exe"=
"c:\\Program Files\\NX Client for Windows\\bin\\nxssh.exe"=
"d:\\devtools\\bea101\\jdk150_11\\jre\\bin\\java.exe"=
"d:\\Ariba\\Demo9r1\\Upstream\\Server\\3rdParty\\jre\\NT\\1.5.0\\bin\\java.exe"=
"c:\\devtools\\jdk1.5.0_14\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\devtools\\bea101\\jdk150_11\\bin\\java.exe"=
"d:\\Ariba\\JPMC9r1\\Downstream\\Server\\3rdParty\\jre\\NT\\1.5.0\\bin\\java.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Documents and Settings\\kveerappa\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6129:TCP"= 6129:TCP:Dameware
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"2015:UDP"= 2015:UDP:Windows Media Format SDK (IEXPLORE.EXE)
"2014:UDP"= 2014:UDP:Windows Media Format SDK (IEXPLORE.EXE)
"2017:UDP"= 2017:UDP:Windows Media Format SDK (IEXPLORE.EXE)
R0 AES-256;AES-256;c:\windows\system32\drivers\AES256.sys [9/5/2007 3:20 AM 19712]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [11/25/2009 11:50 PM 207792]
R0 SgeFlt;SgeFlt;c:\windows\system32\drivers\SGEFLT.sys [9/5/2007 3:20 AM 62720]
R1 FSLX;FSLX;c:\windows\system32\drivers\fslx.sys [7/21/2008 12:01 AM 192256]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [11/26/2009 12:42 AM 108289]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [11/25/2009 11:53 PM 112592]
R2 MKSAUTH;MKSAUTH;c:\windows\system32\mksauth.exe [7/25/2007 12:07 PM 94168]
R2 MKSRlogind;MKS Rlogind;c:\devtools\MKS\bin\rlogind.exe [6/7/2007 12:41 PM 69848]
R2 MKSSecureSH;MKS Secure Shell Service;c:\devtools\MKS\bin\secshd.exe [7/16/2007 6:11 PM 360408]
R2 NuTCRACKERService;NuTCRACKER Service;c:\windows\system32\nutsrv4.exe [7/20/2007 3:31 PM 315424]
R2 OracleServiceARIBA1;OracleServiceARIBA1;c:\devtools\ora10.2.0\bin\ORACLE.EXE ARIBA1 –> c:\devtools\ora10.2.0\bin\ORACLE.EXE ARIBA1 [?]
R2 REXECD;REXECD;c:\devtools\MKS\mksnt\rexecd.exe [7/25/2007 12:10 PM 102360]
R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [6/17/2009 3:17 PM 434864]
R3 DwMirror;DwMirror;c:\windows\system32\drivers\DamewareMini.sys [2/7/2007 4:30 PM 3712]
S2 OracleDBConsoleARIBA1;OracleDBConsoleARIBA1;c:\devtools\ora10.2.0\BIN\nmesrvc.exe [3/24/2009 10:11 PM 24064]
S2 OracleOraDb10g_home1TNSListener;OracleOraDb10g_home1TNSListener;c:\devtools\ora10.2.0\BIN\TNSLSNR –> c:\devtools\ora10.2.0\BIN\TNSLSNR [?]
S2 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" –> c:\program files\Symantec AntiVirus\SavRoam.exe [?]
S3 CSVirtA;Cisco Systems SSL VPN Adapter;c:\windows\system32\drivers\CSVirtA.sys [3/3/2009 11:20 PM 22136]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [?]
S3 OracleOraHome92Agent;OracleOraHome92Agent;d:\devtools\oracle\ora92\bin\agntsrvc.exe [4/26/2002 6:59 AM 28944]
S3 OracleOraHome92HTTPServer;OracleOraHome92HTTPServer;d:\devtools\oracle\ora92\Apache\Apache\Apache.exe [4/18/2002 11:32 AM 4096]
S3 OracleOraHome92SNMPPeerEncapsulator;OracleOraHome92SNMPPeerEncapsulator;d:\devtools\oracle\ora92\bin\encsvc.exe [2/12/2002 9:53 PM 187392]
S3 OracleOraHome92SNMPPeerMasterAgent;OracleOraHome92SNMPPeerMasterAgent;d:\devtools\oracle\ora92\bin\agntsvc.exe [2/12/2002 9:53 PM 254464]
S3 OracleServiceARIBA;OracleServiceARIBA;d:\devtools\oracle\ora92\bin\ORACLE.EXE ARIBA –> d:\devtools\oracle\ora92\bin\ORACLE.EXE ARIBA [?]
S3 Tomcat6;Apache Tomcat;d:\kris\ProgramFiles\Tomcat 6.0\bin\tomcat6.exe [1/28/2008 5:39 PM 57344]
S4 MKSTelnetd;MKS Telnetd;c:\windows\system32\telnetd.exe [6/7/2007 12:40 PM 114904]
S4 OracleJobSchedulerARIBA1;OracleJobSchedulerARIBA1;c:\devtools\ora10.2.0\Bin\extjob.exe ARIBA1 –> c:\devtools\ora10.2.0\Bin\extjob.exe ARIBA1 [?]
S4 RSHD;RSHD;c:\devtools\MKS\mksnt\rshd.exe [7/25/2007 12:10 PM 114648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
vvdsvc REG_MULTI_SZ vvdsvc
.
Contents of the 'Scheduled Tasks' folder
2009-11-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1604221776-839522115-64179Core.job
- c:\documents and settings\kveerappa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 08:31]
2009-11-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1604221776-839522115-64179UA.job
- c:\documents and settings\kveerappa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 08:31]
2009-11-26 c:\windows\Tasks\User_Feed_Synchronization-{289DB8EB-F584-4124-8768-93085DB71593}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://web.ariba.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: %SystemRoot%\system32\nutafun4.dll
TCP: {7C93048F-1CEF-4378-819F-0E6BDDA55A30} = 10.1.1.10,10.1.1.11
DPF: {25C89FF5-4A85-4183-81F2-6C0C1B514297} - hxxps://crm.ariba.com/hi/18382/applets/SiebelAx_HI_Client.cab
DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} - hxxps://snv-acdcasa/CACHE/stc/1/binaries/stcweb.cab
DPF: {31C799C0-32B1-4EFE-87FC-CF506C14338B} - hxxps://crm.ariba.com/hi/18382/applets/SiebelAx_OutBound_mail.cab
DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} - hxxps://rapgh.ariba.com/CACHE/stc/1/binaries/vpnweb.cab
DPF: {61803B6E-0994-4C05-AC45-1FE2EEDADECB} - hxxps://zinfandel.ariba.com/DemoACM/ariba/resource/en_US/lib/winXP/clientautomation.cab
DPF: {8AFC9162-C354-4022-9E7E-ED4D41A9A284} - hxxp://kveerappa1.ariba.com/DemoAribaASM/ariba/resource/en_US/lib/clientautomation.cab
DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} - hxxps://crm.ariba.com/hi/18382/applets/SiebelAx_Desktop_Integration.cab
DPF: {FDF527BA-DDDA-11D3-AA82-006094EB09CB} - hxxp://help/aspnet_client/Altiris_AppWeaver/6_0_sp3/lib/AeXClipboard.CAB
FF - ProfilePath - c:\documents and settings\kveerappa\Application Data\Mozilla\Firefox\Profiles\3jr8cvzb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p;=
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p;=
FF - prefs.js: network.proxy.ftp - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.gopher - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.http - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.socks - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.ssl - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.type - 2
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
ShellIconOverlayIdentifiers-{ba930330-a721-11d3-a7b9-00500464ee16} - Sgedrse.Dll
ShellIconOverlayIdentifiers-{2030D939-54A7-4fea-9B06-49EA77EFC87F} - Sgedrse.Dll
HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
AddRemove-Broadcom 802.11b Network Adapter - c:\program files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe verbose
AddRemove-e84c95559d72a4b073d4840a41180d31 - d:\devtools\Tibco\_uninst\uninstallTibco.exe
AddRemove-NVIDIA Drivers - c:\windows\system32\nvudisp.exe UninstallGUI
AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-{D1DB41B3-0415-4D96-B53B-4B02B9AAD23A}-Visible - c:\documents and settings\zeus\Local Settings\Application Data\{D1DB41B3-0415-4D96-B53B-4B02B9AAD23A}\setup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-26 09:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OracleOraDb10g_home1TNSListener]
"ImagePath"="c:\devtools\ora10.2.0\BIN\TNSLSNR "
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OracleOraHome92PagingServer]
"ImagePath"="d:\devtools\oracle\ora92/bin/pagntsrv.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OracleOraHome92TNSListener]
"ImagePath"="d:\devtools\oracle\ora92\BIN\TNSLSNR "
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1744)
c:\windows\system32\WININET.dll
c:\windows\system32\SGLogEx.dll
c:\windows\system32\SGLogNotification.dll
c:\windows\system32\GetUserSid.dll
- - - - - - - > 'lsass.exe'(1808)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(5236)
c:\windows\system32\WININET.dll
c:\program files\Utimaco\SafeGuard Easy\SgMsgBhk.dll
c:\devtools\Perforce\p4exp.dll
c:\program files\Utimaco\SafeGuard Easy\SgeDrse.dll
c:\program files\Utimaco\SafeGuard Easy\SgeUtil.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\windows\system32\ConnAPI.DLL
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\windows\system32\CDRTC.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\program files\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Cisco Systems\SSL VPN Client\agent.exe
c:\windows\System32\bcmwltry.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Altiris\Altiris Agent\AeXNSAgent.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
d:\devtools\Apache Group\Apache2\bin\Apache.exe
d:\devtools\Apache Group\Apache2\bin\Apache.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\windows\system32\DWRCS.EXE
c:\program files\Dell\OpenManage\Client\Iap.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\MySQL\MySQL Server 5.1\bin\mysqld.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\windows\system32\nvsvc32.exe
d:\devtools\oracle\ora92\bin\omtsreco.exe
c:\devtools\ora10.2.0\bin\isqlplussvc.exe
c:\devtools\ora10.2.0\bin\ORACLE.EXE
c:\program files\Utimaco\SafeGuard Easy\SgeCtl.exe
c:\windows\system32\SgLogPlayer.exe
c:\windows\system32\StacSV.exe
c:\program files\RealVNC\VNC4\WinVNC4.exe
c:\program files\Utimaco\SafeGuard Easy\WksCfgSrv.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
c:\program files\Altiris\Altiris Agent\AeXAgentUIHost.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-11-26 09:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-26 14:24
Pre-Run: 20,016,668,672 bytes free
Post-Run: 19,984,228,352 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 00779E1F90B3FA4A99686950E5162EE2