OK-here's what I did and what happened:
First, deleted old desktop copy of Combofix and downloaded fresh one from link 1, renaming it iexplore.exe before saving it to desktop.
Deactivated Sophos and tried to start Combofix- got green status bar and then a blue screen message of a crash dump with Process_has_locked_files.
Restarted in safe mode.
Attempted to restart Combofix. This time got a security message that I had a corrupted copy of Combofix and should delete it. This was followed by a message from Combofix that Lavasoft was still running and I should disable it. I could not find Lavasoft in my programs, so I elected to run Combofix anyway. (I presume the first security message was bogus to stop me from running combofix?)
To my surprise, Combofix began to run through its stages, and after what seemed like a long wait, generated the following log:
ComboFix 11-02-28.03 - gbarron 02/28/2011 23:35:47.1.2 - x86 MINIMAL
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3535.2898 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Sophos Anti-Virus *Disabled/Updated* {479CCF92-4960-B3E0-7373-BF453B467D2C}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B}
SP: Sophos Anti-Virus *Disabled/Updated* {FCFD2E76-6F5A-BC6E-49C3-843740C13791}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\install.exe
c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
c:\users\gbarron\AppData\Roaming\xssend2
c:\users\pcimage\AppData\Roaming\desktop.ini
c:\users\test\Desktop\Internet Explorer.lnk
—– BITS: Possible infected sites —–
hxxp://wus-vs:8530
.
((((((((((((((((((((((((( Files Created from 2011-02-01 to 2011-03-01 )))))))))))))))))))))))))))))))
.
2011-03-01 05:05 . 2011-03-01 05:07 ——– d—–w- c:\users\gbarron\AppData\Local\temp
2011-03-01 05:05 . 2011-03-01 05:05 ——– d—–w- c:\users\test\AppData\Local\temp
2011-03-01 05:05 . 2011-03-01 05:05 ——– d—–w- c:\users\mhurst99\AppData\Local\temp
2011-03-01 05:05 . 2011-03-01 05:05 ——– d—–w- c:\users\lfrownfelter2\AppData\Local\temp
2011-03-01 05:05 . 2011-03-01 05:05 ——– d—–w- c:\users\bhowell\AppData\Local\temp
2011-03-01 05:05 . 2011-03-01 05:05 ——– d—–w- c:\users\Administrator\AppData\Local\temp
2011-03-01 04:18 . 2011-03-01 04:22 ——– d—–w- C:\32788R22FWJFW
2011-02-19 01:51 . 2011-02-19 01:51 ——– d—–w- c:\program files\Common Files\Java
2011-02-19 01:49 . 2011-02-19 01:49 472808 —-a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-02-19 01:49 . 2011-02-19 01:49 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-18 06:12 . 2011-02-18 06:12 ——– d—–w- c:\program files\ESET
2011-02-16 15:57 . 2011-02-16 15:57 59904 –sha-r- c:\windows\system32\sl_anetr.dll
2011-02-15 14:27 . 2011-01-13 09:41 5890896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D9B74AEE-DFBB-458E-8011-6F6B6569D8F6}\mpengine.dll
2011-02-11 19:02 . 2010-12-28 15:55 413696 —-a-w- c:\windows\system32\odbc32.dll
2011-02-11 19:02 . 2010-12-28 15:53 253952 —-a-w- c:\program files\Common Files\System\ado\msadox.dll
2011-02-11 19:02 . 2010-12-28 15:53 241664 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll
2011-02-11 19:02 . 2010-12-28 15:53 708608 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2011-02-11 19:02 . 2010-12-28 15:53 57344 —-a-w- c:\program files\Common Files\System\msadc\msadcs.dll
2011-02-11 19:02 . 2010-12-28 15:53 180224 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll
2011-02-11 19:01 . 2010-06-30 22:28 1203032 —-a-w- c:\windows\system32\ntdll.dll
2011-02-11 19:00 . 2010-12-14 14:49 1169408 —-a-w- c:\windows\system32\sdclt.exe
2011-02-11 05:54 . 2011-02-11 05:54 388096 —-a-r- c:\users\gbarron\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-11 05:54 . 2011-02-11 05:54 ——– d—–w- c:\program files\Trend Micro
2011-02-04 20:12 . 2011-02-04 20:10 131824 —-a-w- c:\windows\system32\sdccoinstaller.dll
2011-02-04 20:12 . 2011-02-04 20:12 ——– d—–w- c:\programdata\Sophos Web Intelligence
2011-02-04 20:12 . 2011-02-04 20:12 ——– d—–w- c:\program files\Common Files\Cisco Systems
2011-02-04 20:12 . 2011-02-04 20:09 28912 —-a-w- c:\windows\system32\SophosBootTasks.exe
2011-02-04 20:10 . 2011-02-04 20:10 122360 —-a-w- c:\windows\system32\drivers\savonaccess.sys
2011-02-04 20:09 . 2011-02-04 20:09 23928 —-a-w- c:\windows\system32\drivers\sdcfilter.sys
2011-02-04 20:09 . 2011-02-04 20:09 22536 —-a-w- c:\windows\system32\drivers\SophosBootDriver.sys
2011-02-02 07:55 . 2011-02-13 21:46 ——– d—–w- c:\program files\Emsisoft Anti-Malware
2011-01-30 19:57 . 2011-01-30 19:57 103864 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-01-30 19:57 . 2011-01-30 19:57 103864 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 23:09 . 2010-03-26 12:01 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 23:08 . 2010-03-26 12:01 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-04 06:35 . 2009-06-15 19:21 249856 ——w- c:\windows\Setup1.exe
2010-12-04 06:35 . 2009-06-15 19:21 73216 —-a-w- c:\windows\ST6UNST.EXE
2010-12-04 06:25 . 2010-12-04 06:25 286720 —-a-w- c:\windows\iun506.exe
2006-05-03 09:06 163328 –sh–r- c:\windows\System32\flvDX.dll
2007-02-21 10:47 31232 –sh–r- c:\windows\System32\msfDX.dll
2008-03-16 12:30 216064 –sh–r- c:\windows\System32\nbDX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2007-07-23 5803368]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-04 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"picon"="c:\program files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2008-06-19 367128]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-08 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-08 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-08 145944]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2008-05-30 593920]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-10-17 442536]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-06-04 68592]
"WD Button Manager"="WDBtnMgr.exe" [2010-01-15 364544]
"LTCM Client"="c:\program files\LTCM Client\ltcmClient.exe" [2008-12-24 1540288]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"Sophos AutoUpdate Monitor"="c:\program files\Sophos\AutoUpdate\almon.exe" [2010-09-30 439536]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2007-07-23 5803368]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Amazon Unbox.lnk - c:\program files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe [2010-9-13 97384]
Dell ControlPoint System Manager.lnk - c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe [2008-8-18 1186896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"MaxGPOScriptWait"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"ReportControllerMissing"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Sophos\SOPHOS~1\sophos_detoured.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1422877143-578114725-926709054-12956\Scripts\Logon\0\0]
"Script"=logonedited.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1422877143-578114725-926709054-28461\Scripts\Logon\0\0]
"Script"=usercommconfig.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1422877143-578114725-926709054-28461\Scripts\Logon\1\0]
"Script"=logonedited.vbs
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
2010-03-03 16:35 524632 —-a-w- c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 22:16 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
R0 pegcbrhq;pegcbrhq; [x]
R1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys [2011-02-04 122360]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_2311653e\aestsrv.exe [2008-06-27 77824]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [2008-06-03 386328]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [2008-11-11 808296]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [2008-11-11 20840]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe [2008-08-18 453712]
R2 gupdate1c9e522293f8bdb;Google Update Service (gupdate1c9e522293f8bdb);c:\program files\Google\Update\GoogleUpdate.exe [2009-06-04 133104]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2011-02-04 163056]
R2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [2011-02-04 97520]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 swi_service;Sophos Web Intelligence Service;c:\program files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2011-02-04 1541360]
R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2008-06-19 2058776]
R3 CCIDFILTER;Broadcom Smart Card Reader Filter Driver;c:\windows\system32\DRIVERS\ccidflt.SYS [2008-11-11 12840]
R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\Drivers\cvusbdrv.sys [2008-11-11 32808]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y6032.sys [2008-04-04 224384]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-06-30 112128]
R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-06-26 3662848]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\DRIVERS\OA001Ufd.sys [2008-11-26 133472]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\DRIVERS\OA001Vid.sys [2008-12-26 279488]
R3 PeerDistSvc;BranchCache;c:\windows\System32\svchost.exe [2008-01-19 21504]
R3 sdcfilter;sdcfilter;c:\windows\system32\DRIVERS\sdcfilter.sys [2011-02-04 23928]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys [2011-02-04 22536]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-06-22 64160]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-03-03 1029456]
— Other Services/Drivers In Memory —
*NewlyCreated* - ECACHE
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
PeerDist REG_MULTI_SZ PeerDistSvc
.
Contents of the 'Scheduled Tasks' folder
2010-03-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 16:35]
2011-02-28 c:\windows\Tasks\Daily-12pm.job
- c:\program files\Sophos\Sophos Anti-Virus\BackgroundScanClient.exe [2011-02-04 20:09]
2010-03-26 c:\windows\Tasks\Driver Robot.job
- c:\program files\Driver Robot\1.1.0.14\DriverRobot.exe [2009-10-23 21:51]
2010-10-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-04 14:38]
2010-10-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-04 14:38]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.mercyhurst.edu/Pages/default.aspx
uInternet Settings,ProxyOverride =
Trusted Zone: mercyhurst.edu\campusmanager
Trusted Zone: microsoft.com
DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} - file:///D:/LTOCX14N.cab
FF - ProfilePath -
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
HKCU-Run-ehSfAxdeCUNMnk.exe - c:\programdata\ehSfAxdeCUNMnk.exe
HKCU-Run-RgFqlXFJatY - c:\progra~2\RgFqlXFJatY.exe
HKCU-Run-ImxpkgNQo7ZcXknT - c:\progra~2\ImxpkgNQo7ZcXknT.exe
HKCU-Run-3qPbZBGJ - c:\progra~2\3qPbZBGJ.exe
HKCU-Run-bTl53SCxZd7Lh - c:\programdata\bTl53SCxZd7Lh.exe
HKLM-Run-SysTrayApp - %ProgramFiles%\IDT\WDM\sttray.exe
HKLM-RunOnce- - (no file)
AddRemove-Copy Utility - c:\program files\EPSON\Copy Utility\Uninst.isu
AddRemove-PF 2450 PHOTO Guide - c:\program files\EPSON\2450 PHOTO\DeIsL1.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-03-01 00:07
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos Message Router]
"ImagePath"="\"c:\program files\Sophos\Remote Management System\RouterNT.exe\" -service -name Router -ORBListenEndpoints iiop://:8193/ssl_port=8194"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-03-01 00:24:30
ComboFix-quarantined-files.txt 2011-03-01 05:24
Pre-Run: 19,978,457,088 bytes free
Post-Run: 20,229,402,624 bytes free
- - End Of File - - 3422DF2096B5D2140480992C1BE200A6