DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 21:58:20.20 on Mon 04/19/2010
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2039.1309
[GMT -7:00]
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled*
(Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device
Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdController.exe
C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdServer.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\Mixer.exe
C:\Documents and Settings\Strongbad\Local Settings\Application Data\vma.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wpabaln.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Strongbad\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.bluegrassguitar.com/
uWindow Title = Microsoft Internet Explorer provided by Comcast
mWindow Title = Microsoft Internet Explorer provided by Comcast
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
BHO: Adobe PDF Reader Link Helper:
{06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program
files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: SpywareGuardDLBLOCK.CBrowserHelper:
{4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program
files\spywareguard\dlprotect.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} -
c:\program files\java\jre1.5.0_09\bin\ssv.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program
files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [updateMgr] "c:\program files\adobe\acrobat
7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [C-Media Mixer] Mixer.exe /startup
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album
starter edition\3.2\apps\apdproxy.exe"
mRun: [Ssefonul] rundll32.exe "c:\windows\urunoses.dll",Startup
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program
files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\docume~1\strong~1\startm~1\programs\startup\erunta~1.lnk
- c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\strong~1\startm~1\programs\startup\spywar~1.lnk
- c:\program files\spywareguard\sgmain.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk
- c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
IE: {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/
IE: {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/
IE: {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network
Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program
files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC} - c:\program
files\java\jre1.5.0_09\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} -
c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
DPF: {00000161-0000-0010-8000-00AA00389B71} -
hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab
DPF: {3334504D-9980-0010-8000-00AA00389B71} -
hxxp://download.microsoft.com/download/0/C/8/0C8EDFAB-30BC-4792-898E-2DABE27B2C4D/mp43dmo.CAB
DPF: {33564D57-0000-0010-8000-00AA00389B71} -
hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
hxxp://software-dl.real.com/044645566f5d94c80e23/netzip/RdxIE601.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} -
hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1126756539921
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} -
hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab
DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} -
hxxp://www.crucial.com/controls/cpcScanner.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} -
hxxp://by1fd.bay1.hotmail.msn.com/activex/HMAtchmt.ocx
Notify: igfxcui - igfxsrvc.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -
c:\windows\system32\WPDShServiceObj.dll
SEH: CShellExecuteHookImpl Object:
{54d9498b-cf93-414f-8984-8ce7fde0d391} - c:\program
files\ewido\security suite\shellhook.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} -
c:\program files\spywareguard\spywareguard.dll
LSA: Notification Packages = scecli scecli
================= FIREFOX ===================
FF - ProfilePath -
c:\docume~1\strong~1\applic~1\mozilla\firefox\profiles\9kum25y4.default\
FF - prefs.js: browser.startup.homepage -
hxxps://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=https%3A%2F%2Fmail.google.com%2Fmail%2F%3Fshva%3D1%26nsr%3D0%26ui%3Dhtml%26zy%3Dl FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\strongbad\application
data\mozilla\firefox\profiles\9kum25y4.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJPI150_09.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - HiddenExtension: XULRunner:
{69C9FF6A-7C74-41BA-AE64-1ADCCFC3A460} - c:\documents and
settings\strongbad\local settings\application
data\{69C9FF6A-7C74-41BA-AE64-1ADCCFC3A460}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 IFP300;iriver Internet Audio Player
IFP-300;c:\windows\system32\drivers\ifp300.sys [2006-6-7 14531]
R0 Pnp680;SiI 680 ATA
Controller;c:\windows\system32\drivers\pnp680.sys [2002-3-15 37031]
R1 ewido security suite driver;ewido security suite driver;c:\program
files\ewido\security suite\guard.sys [2004-11-22 3072]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2004-2-9 301200]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common
files\symantec shared\ccEvtMgr.exe [2004-6-9 255096]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common
files\symantec shared\ccSetMgr.exe [2004-6-9 242808]
R2 ewido security suite control;ewido security suite
control;c:\program files\ewido\security suite\ewidoctrl.exe
[2004-11-11 16448]
R2 RosettaStoneLtdController;RosettaStoneLtdController;c:\program
files\rosettastoneltdservices\RosettaStoneLtdController.exe
[2007-10-31 354648]
R2 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe
[2004-8-2 173392]
R2 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys
[2004-2-9 37008]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec
antivirus\Rtvscan.exe [2004-8-2 1267024]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100416.003\naveng.sys
[2010-4-19 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100416.003\navex15.sys
[2010-4-19 1324720]
S2 OxSer;PCI Serial Driver;c:\windows\system32\drivers\oxser.sys
[2004-12-30 54584]
S2 PARXPORT;PCI Parallel
Driver;c:\windows\system32\drivers\parxport.sys [2004-12-30 13608]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common
files\symantec shared\ccPwdSvc.exe [2004-6-9 87160]
S3 cmudax;C-Media Azalia Audio
Interface;c:\windows\system32\drivers\cmudax.sys –>
c:\windows\system32\drivers\cmudax.sys [?]
S3 HwIOctl;HwIOctl;\??\c:\program files\setup files\ms-7058
v1.40\hwioctl.sys –> c:\program files\setup files\ms-7058
v1.40\HwIOctl.sys [?]
S3 Ipd30ci;Ipd30ci; [x]
S4 ewido security suite guard;ewido security suite guard;c:\program
files\ewido\security suite\ewidoguard.exe [2006-2-6 151616]
============== File Associations ===============
.exe=secfile
=============== Created Last 30 ================
2010-04-20 02:16:15 160 —-a-w- c:\documents and
settings\strongbad\defogger_reenable
2010-04-19 23:42:36 0 d—–w- c:\docume~1\alluse~1\applic~1\avG
2010-04-19 15:35:42 0 d—–w- c:\docume~1\strong~1\applic~1\DAEMON Tools Lite
2010-04-19 15:35:16 0 d—–w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
==================== Find3M ====================
2010-03-30 07:46:30 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-30 07:45:52 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2006-08-15 17:46:45 604 -c-ha-w- c:\program files\STLL Notifier
2010-01-19 06:05:14 32768 –sha-w- c:\windows\system32\config\systemprofile\local
settings\history\history.ie5\mshist012010011820100119\index.dat
2010-01-16 05:04:01 16384 –sha-w- c:\windows\temp\cookies\index.dat
2010-01-16 05:04:01 16384 –sha-w- c:\windows\temp\history\history.ie5\index.dat
2010-01-16 05:04:01 49152 –sha-w- c:\windows\temp\temporary internet
files\content.ie5\index.dat
============= FINISH: 22:03:58.73 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-04-19 22:07:01
Windows 5.1.2600 Service Pack 2
Running: s9lbh5ej.exe; Driver: C:\DOCUME~1\STRONG~1\LOCALS~1\Temp\pwtyypoc.sys
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device -> \Driver\atapi \Device\Harddisk0\DR0 8A7EA856
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
—- EOF - GMER 1.0.15 —-