Spyware / Malware / Virus Removal
google redirect and "choose program to open file" message
30 min read
mrmarky
Topic Starter
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 14:47:53.26 on Thu 03/31/2011
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.986 [GMT -4:00]
AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning enabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Symantec Endpoint Protection *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *enabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
c:\drivers\media\sthda_5.10.0.6261_b3992798038074661ad78e0fdd271a33\stacsv.exe
svchost.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Dell\Reader 2.0\DVMExportService.exe
C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
C:\Program Files\SalesLogix\SLXSystem.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Marimba\Tuner\Tuner.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\WINDOWS\OA015Mon.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Dell\Reader 2.0\DellBtrEvent.exe
C:\Program Files\Citrix\ICA Client\concentr.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Citrix\ICA Client\wfcrun32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\SalesLogix\SalesLogix.exe
C:\Program Files\Marimba\Tuner\lib\minituner.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Citrix\ICACLI~1\WFICA32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\mark.phelps\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [OA015Mon] c:\windows\OA015Mon.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [DellControlPoint] "c:\program files\dell\dell controlpoint\Dell.ControlPoint.exe"
mRun: [DellBtrEvent] c:\program files\dell\reader 2.0\DellBtrEvent.exe
mRun: [ConnectionCenter] "c:\program files\citrix\ica client\concentr.exe" /startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dellco~1.lnk - c:\program files\dell\dell controlpoint\system manager\DCPSysMgr.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Notify: ckpNotify - ckpNotify.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-3-30 64512]
R0 stdflt;Disk Filter Driver for Accelerometer;c:\windows\system32\drivers\stdfltn.sys [2011-1-5 17072]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [2010-7-14 65584]
R1 DVMIO;DVMIO;c:\program files\dell\reader 2.0\dvmio.sys [2010-2-1 18192]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\dell\dell controlpoint\DCPButtonSvc.exe [2009-11-20 278304]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2011-2-15 108392]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2011-2-15 108392]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\dell\dell controlpoint\system manager\DCPSysMgrSvc.exe [2010-2-8 376688]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\program files\dell\reader 2.0\DVMExportService.exe [2009-8-3 327680]
R2 InstallFilterService;FF Install Filter Service;c:\program files\stmicroelectronics\accelerometerp11\InstallFilterService.exe [2011-1-5 60928]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-3-30 1405384]
R2 risdpcie;risdpcie;c:\windows\system32\drivers\risdpe86.sys [2011-1-5 47616]
R2 SalesLogix System;SalesLogix System Service;c:\program files\saleslogix\SLXSystem.exe [2010-11-22 385024]
R2 Scap;SecureClient Application Policy Module;c:\windows\system32\drivers\scap.sys [2011-1-5 17456]
R2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec\symantec endpoint protection\Rtvscan.exe [2011-2-15 1831024]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [2011-1-5 670128]
R2 WKEndpoint;WK Endpoint;c:\program files\marimba\tuner\Tuner.exe [2010-1-19 36957]
R3 Acceler;Accelerometer Service;c:\windows\system32\drivers\Accelern.sys [2011-1-5 42672]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2011-1-5 113664]
R3 CtAudDrv;Provides advanced audio effects for audio devices.;c:\windows\system32\drivers\CtAudDrv.sys [2011-1-5 134144]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [2011-1-5 143968]
R3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [2011-1-5 33832]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [2011-1-5 167080]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-1-5 102448]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [2011-1-5 2041904]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2011-1-5 132480]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20110330.040\NAVENG.SYS [2011-3-31 86136]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20110330.040\NAVEX15.SYS [2011-3-31 1393144]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2011-1-5 58600]
R3 OA015Afx;Provides a software interface to control audio effects of OA015 camera.;c:\windows\system32\drivers\OA015Afx.sys [2011-1-5 134144]
R3 OA015Vid;Creative Camera OA015 Function Driver;c:\windows\system32\drivers\OA015Vid.sys [2011-1-5 273568]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys –> c:\windows\system32\drivers\is3srv.sys [?]
S0 szkg5;szkg5;c:\windows\system32\drivers\szkg.sys –> c:\windows\system32\drivers\szkg.sys [?]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys –> c:\windows\system32\drivers\szkgfs.sys [?]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2009-7-14 23888]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-3-30 15232]
S3 OMVA;VPN-1 SecureClient Adapter;c:\windows\system32\drivers\OMVA.sys [2011-1-5 14924]
============== File Associations ===============
scrfile="%1" %*
=============== Created Last 30 ================
2011-03-30 13:15 472,808 a——- c:\windows\system32\deployJava1.dll
2011-03-30 13:09 –d—– c:\docume~1\alluse~1\applic~1\Applications
2011-03-30 11:31 64,512 a——- c:\windows\system32\drivers\Lbd.sys
2011-03-30 11:31 98,392 a——- c:\windows\system32\drivers\SBREDrv.sys
2011-03-30 11:20 -cd-h— c:\docume~1\alluse~1\applic~1\{9937DA50-1322-492A-A1C8-1911CDD1BD57}
2011-03-30 11:19 –d—– c:\program files\Lavasoft
2011-03-30 11:13 –d—– c:\windows\system32\appmgmt
2011-03-30 10:16 720 a——- c:\windows\system32\drivers\kgpcpy.cfg
2011-03-30 10:07 –d—– c:\docume~1\alluse~1\applic~1\STOPzilla!
2011-03-25 22:57 25,856 ac—— c:\windows\system32\dllcache\usbprint.sys
2011-03-25 22:57 25,856 a——- c:\windows\system32\drivers\usbprint.sys
2011-03-25 21:27 135,168 a–shr– c:\windows\system32\nvrspll.dll
2011-03-16 08:29 –d—– c:\docume~1\mark~1.phe\applic~1\ElevatedDiagnostics
==================== Find3M ====================
2011-03-30 08:06 126,439 a——- c:\windows\system32\nvModes.dat
2011-02-15 12:09 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2011-02-15 12:09 60,808 a——- c:\windows\system32\S32EVNT1.DLL
2011-02-15 12:09 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2011-02-15 12:09 806 a——- c:\windows\system32\drivers\SYMEVENT.INF
2011-02-09 09:53 270,848 a——- c:\windows\system32\sbe.dll
2011-02-09 09:53 186,880 a——- c:\windows\system32\encdec.dll
2011-02-05 13:25 82,696 a——- c:\windows\system32\lmdimon8.dll
2011-02-02 03:58 2,067,456 a——- c:\windows\system32\mstscax.dll
2011-01-27 07:57 677,888 a——- c:\windows\system32\mstsc.exe
2011-01-21 10:44 439,296 a——- c:\windows\system32\shimgvw.dll
2011-01-07 10:09 290,048 a——- c:\windows\system32\atmfd.dll
============= FINISH: 14:48:08.12 ===============
Blottedisk
Hi mrmarky,
Welcome to WhattheTech. My name is Blottedisk and I will be helping you with your malware issues. Before we delve into this, please take a look at the following notes:
You have 2 Antivirus programs running at the same time: Lavasoft and Symantec. This can cause issues such as system slowdown, conflicts, errors, false positives, ect… Please disable one of them: How to Disable Security Applications.
——————————————————-
Please follow these steps:
Step 1 | Your current version of DDS is outdated. Please delete DDS.exe, as well as DDS.txt and Attach.txt. After that, Download DDS from any of the links below:
Link 1
Link 2
Link 2
——————————————————————–
Step 2 | Please download GMER from one of the following locations and save it to your desktop:
Main Mirror - This version will download a randomly named file (Recommended)
Zipped Mirror - This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
——————————————————————–
Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.
[external image: Posted Image]
[external image: Posted Image]
Click the image to enlarge it
Step 3 | Please download MBRCheck.exe to your desktop.
Welcome to WhattheTech. My name is Blottedisk and I will be helping you with your malware issues. Before we delve into this, please take a look at the following notes:
- Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
- Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.
- The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.
You have 2 Antivirus programs running at the same time: Lavasoft and Symantec. This can cause issues such as system slowdown, conflicts, errors, false positives, ect… Please disable one of them: How to Disable Security Applications.
——————————————————-
Please follow these steps:
Step 1 | Your current version of DDS is outdated. Please delete DDS.exe, as well as DDS.txt and Attach.txt. After that, Download DDS from any of the links below:
Link 1
Link 2
Link 2
——————————————————————–
- Save it to your desktop.
- Please disable any anti-malware program that will block scripts from running before running DDS.
- Double-Click on dds and a command window will appear. This is normal.
- Shortly after two logs will appear:
- DDS.txt
- Attach.txt
- A window will open instructing you save & post the logs.
- Save the logs to a convenient place such as your desktop.
- Post the contents of the DDS.txt report in your next reply.
- Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Step 2 | Please download GMER from one of the following locations and save it to your desktop:
Main Mirror - This version will download a randomly named file (Recommended)
Zipped Mirror - This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
——————————————————————–
- Disconnect from the Internet and close all running programs.
- Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
- Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.
[external image: Posted Image]
- GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
- If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
- Make sure all options are checked except:
- IAT/EAT
- Drives/Partition other than Systemdrive, which is typically C:\
- Show All (This is important, so do not miss it.)
[external image: Posted Image]
Click the image to enlarge it
- Now click the Scan button. If you see a rootkit warning window, click OK.
- When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
- Click the Copy button and paste the results into your next reply.
- Exit GMER and re-enable all active protection when done.
Step 3 | Please download MBRCheck.exe to your desktop.
- Be sure to disable your security programs
- Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
- A window will open on your desktop
- if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
- If nothing unusual is found just press Enter
- A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
- Please post the contents of that file.
mrmarky
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 21:45:40.50 on Thu 03/31/2011
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1162 [GMT -4:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Symantec Endpoint Protection *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
c:\drivers\media\sthda_5.10.0.6261_b3992798038074661ad78e0fdd271a33\stacsv.exe
svchost.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Dell\Reader 2.0\DVMExportService.exe
C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
C:\Program Files\SalesLogix\SLXSystem.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Marimba\Tuner\Tuner.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Marimba\Tuner\lib\jre\bin\java.exe
C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\WINDOWS\OA015Mon.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
C:\Program Files\Dell\Reader 2.0\DellBtrEvent.exe
C:\Program Files\Citrix\ICA Client\concentr.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Citrix\ICA Client\wfcrun32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Documents and Settings\mark.phelps\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [OA015Mon] c:\windows\OA015Mon.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [DellControlPoint] "c:\program files\dell\dell controlpoint\Dell.ControlPoint.exe"
mRun: [DellBtrEvent] c:\program files\dell\reader 2.0\DellBtrEvent.exe
mRun: [ConnectionCenter] "c:\program files\citrix\ica client\concentr.exe" /startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dellco~1.lnk - c:\program files\dell\dell controlpoint\system manager\DCPSysMgr.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Notify: ckpNotify - ckpNotify.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-3-30 64512]
R0 stdflt;Disk Filter Driver for Accelerometer;c:\windows\system32\drivers\stdfltn.sys [2011-1-5 17072]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [2010-7-14 65584]
R1 DVMIO;DVMIO;c:\program files\dell\reader 2.0\dvmio.sys [2010-2-1 18192]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\dell\dell controlpoint\DCPButtonSvc.exe [2009-11-20 278304]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2011-2-15 108392]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2011-2-15 108392]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\dell\dell controlpoint\system manager\DCPSysMgrSvc.exe [2010-2-8 376688]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\program files\dell\reader 2.0\DVMExportService.exe [2009-8-3 327680]
R2 InstallFilterService;FF Install Filter Service;c:\program files\stmicroelectronics\accelerometerp11\InstallFilterService.exe [2011-1-5 60928]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-3-30 1405384]
R2 risdpcie;risdpcie;c:\windows\system32\drivers\risdpe86.sys [2011-1-5 47616]
R2 SalesLogix System;SalesLogix System Service;c:\program files\saleslogix\SLXSystem.exe [2010-11-22 385024]
R2 Scap;SecureClient Application Policy Module;c:\windows\system32\drivers\scap.sys [2011-1-5 17456]
R2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec\symantec endpoint protection\Rtvscan.exe [2011-2-15 1831024]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [2011-1-5 670128]
R2 WKEndpoint;WK Endpoint;c:\program files\marimba\tuner\Tuner.exe [2010-1-19 36957]
R3 Acceler;Accelerometer Service;c:\windows\system32\drivers\Accelern.sys [2011-1-5 42672]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2011-1-5 113664]
R3 CtAudDrv;Provides advanced audio effects for audio devices.;c:\windows\system32\drivers\CtAudDrv.sys [2011-1-5 134144]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [2011-1-5 143968]
R3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [2011-1-5 33832]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [2011-1-5 167080]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-1-5 102448]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [2011-1-5 2041904]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2011-1-5 132480]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20110331.003\NAVENG.SYS [2011-3-31 86136]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20110331.003\NAVEX15.SYS [2011-3-31 1393144]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2011-1-5 58600]
R3 OA015Afx;Provides a software interface to control audio effects of OA015 camera.;c:\windows\system32\drivers\OA015Afx.sys [2011-1-5 134144]
R3 OA015Vid;Creative Camera OA015 Function Driver;c:\windows\system32\drivers\OA015Vid.sys [2011-1-5 273568]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys –> c:\windows\system32\drivers\is3srv.sys [?]
S0 szkg5;szkg5;c:\windows\system32\drivers\szkg.sys –> c:\windows\system32\drivers\szkg.sys [?]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys –> c:\windows\system32\drivers\szkgfs.sys [?]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2009-7-14 23888]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-3-30 15232]
S3 OMVA;VPN-1 SecureClient Adapter;c:\windows\system32\drivers\OMVA.sys [2011-1-5 14924]
.
=============== File Associations ===============
.
scrfile="%1" %*
.
=============== Created Last 30 ================
.
2011-03-30 17:15:52 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-03-30 17:09:48 ——– d—–w- c:\docume~1\alluse~1\applic~1\Applications
2011-03-30 15:31:38 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-03-30 15:31:16 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-03-30 15:28:10 ——– d—–w- c:\docume~1\mark~1.phe\locals~1\applic~1\Sunbelt Software
2011-03-30 15:20:12 ——– d—–w- c:\docume~1\mark~1.phe\locals~1\applic~1\Temp
2011-03-30 15:20:07 ——– d—–w- c:\docume~1\mark~1.phe\locals~1\applic~1\Google
2011-03-30 15:20:05 ——– dc-h–w- c:\docume~1\alluse~1\applic~1\{9937DA50-1322-492A-A1C8-1911CDD1BD57}
2011-03-30 15:19:53 ——– d—–w- c:\program files\Lavasoft
2011-03-30 15:13:59 ——– d—–w- c:\windows\system32\appmgmt
2011-03-30 14:07:03 ——– d—–w- c:\docume~1\alluse~1\applic~1\STOPzilla!
2011-03-26 02:57:29 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2011-03-26 02:57:29 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2011-03-26 01:27:33 135168 –sha-r- c:\windows\system32\nvrspll.dll
2011-03-16 12:29:03 ——– d—–w- c:\docume~1\mark~1.phe\applic~1\ElevatedDiagnostics
.
==================== Find3M ====================
.
2011-02-15 16:09:44 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2011-02-15 16:06:42 87368 —-a-w- c:\windows\system32\FwsVpn.dll
2011-02-15 16:06:42 107848 —-a-w- c:\windows\system32\SymVPN.dll
2011-02-09 13:53:52 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-05 17:25:34 82696 —-a-w- c:\windows\system32\lmdimon8.dll
2011-02-05 17:25:34 82184 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\lmdippr8.dll
2011-02-02 23:19:39 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58:35 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 —-a-w- c:\windows\system32\atmfd.dll
.
============= FINISH: 21:46:32.73 ===============
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-03-31 22:24:34
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD16 rev.01.0
Running: 2fpwlnbd.exe; Driver: C:\DOCUME~1\MARK~1.PHE\LOCALS~1\Temp\awryyaoc.sys
—- System - GMER 1.0.15 —-
SSDT 889C8680 ZwAlertResumeThread
SSDT 889AA5E0 ZwAlertThread
SSDT 889E25E8 ZwAllocateVirtualMemory
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xB819887E]
SSDT 88A27B18 ZwCreateMutant
SSDT 86B51580 ZwCreateThread
SSDT 889E1B20 ZwFreeVirtualMemory
SSDT 889BDCF0 ZwImpersonateAnonymousToken
SSDT 889BE6D8 ZwImpersonateThread
SSDT 88A100E8 ZwMapViewOfSection
SSDT 889BDA88 ZwOpenEvent
SSDT 88A04388 ZwOpenProcessToken
SSDT 889FF6E0 ZwOpenThreadToken
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation) ZwProtectVirtualMemory [0xB33D38B0]
SSDT 8895D158 ZwResumeThread
SSDT 88AEF8E0 ZwSetContextThread
SSDT 88A08750 ZwSetInformationProcess
SSDT 88A0F508 ZwSetInformationThread
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xB8198BFE]
SSDT 88A456C0 ZwSuspendProcess
SSDT 889AA908 ZwSuspendThread
SSDT 88475268 ZwTerminateProcess
SSDT 889B7AA8 ZwTerminateThread
SSDT 88AC3CD0 ZwUnmapViewOfSection
SSDT 889D5F98 ZwWriteVirtualMemory
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!ZwCallbackReturn + 2C28 805044C4 4 Bytes CALL 4AD8E2EE
.text ntkrnlpa.exe!ZwCallbackReturn + 2D94 80504630 4 Bytes CALL A2D8E735
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB5384380, 0x3E5D05, 0xE8000020]
init C:\WINDOWS\system32\Drivers\OA015Afx.sys entry point in "init" section [0xB1E58D50]
init C:\WINDOWS\system32\Drivers\CtAudDrv.sys entry point in "init" section [0xB1C47D50]
? C:\DOCUME~1\MARK~1.PHE\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] GDI32.dll!TextOutW 77F17EAC 5 Bytes JMP 0099C3B4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] GDI32.dll!ExtTextOutW 77F18086 5 Bytes JMP 0099C8EE
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] GDI32.dll!TextOutA 77F1BA4F 5 Bytes JMP 0099C2E7
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] GDI32.dll!ExtTextOutA 77F1D3FA 5 Bytes JMP 0099C809
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] GDI32.dll!GetGlyphIndicesA 77F3DFE3 5 Bytes JMP 0099CCA5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] GDI32.dll!GetGlyphIndicesW 77F52604 5 Bytes JMP 0099CD6F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E1DF4D9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DrawTextExW 7E42B415 5 Bytes JMP 0099C721
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DrawTextW 7E42D7E2 5 Bytes JMP 0099C55D
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!SetClipboardData 7E430F9E 5 Bytes JMP 0099C1D4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3527F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E352777 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3527BB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DrawTextA 7E43C702 5 Bytes JMP 0099C481
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DrawTextExA 7E43C739 5 Bytes JMP 0099C639
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E352703 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E35273D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E352831 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E20178A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3529F3 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 0099B3C6
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 0099C146
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!send 71AB4C27 5 Bytes JMP 0099BE2F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 0099C050
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 0099B309
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!recv 71AB676F 5 Bytes JMP 0099BED5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0099BF7F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!WSAAsyncGetHostByName 71ABE99D 5 Bytes JMP 0099B75C
.text C:\WINDOWS\system32\SearchIndexer.exe[2520] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] GDI32.dll!TextOutW 77F17EAC 5 Bytes JMP 0092C3B4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] GDI32.dll!ExtTextOutW 77F18086 5 Bytes JMP 0092C8EE
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] GDI32.dll!TextOutA 77F1BA4F 5 Bytes JMP 0092C2E7
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] GDI32.dll!ExtTextOutA 77F1D3FA 5 Bytes JMP 0092C809
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] GDI32.dll!GetGlyphIndicesA 77F3DFE3 5 Bytes JMP 0092CCA5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] GDI32.dll!GetGlyphIndicesW 77F52604 5 Bytes JMP 0092CD6F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 0092B837
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DrawTextExW 7E42B415 5 Bytes JMP 0092C721
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DrawTextW 7E42D7E2 5 Bytes JMP 0092C55D
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!SetClipboardData 7E430F9E 5 Bytes JMP 0092C1D4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3527F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E352777 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3527BB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DrawTextA 7E43C702 5 Bytes JMP 0092C481
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DrawTextExA 7E43C739 5 Bytes JMP 0092C639
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E352703 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E35273D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E352831 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E20178A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3529F3 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 0092B3C6
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 0092C146
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!send 71AB4C27 5 Bytes JMP 0092BE2F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 0092C050
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 0092B309
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!recv 71AB676F 5 Bytes JMP 0092BED5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0092BF7F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!WSAAsyncGetHostByName 71ABE99D 5 Bytes JMP 0092B75C
—- Devices - GMER 1.0.15 —-
Device \Driver\Tcpip \Device\Ip wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
Device \Driver\Tcpip \Device\Tcp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
Device \Driver\Tcpip \Device\Udp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
Device \Driver\Tcpip \Device\RawIp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
Device \Driver\Tcpip \Device\IPMULTICAST wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
—- EOF - GMER 1.0.15 —-
MBRCheck, version 1.2.3
© 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0004000c
Kernel Drivers (total 194):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E5000 \WINDOWS\system32\hal.dll
0xB85A8000 \WINDOWS\system32\KDCOM.DLL
0xB84B8000 \WINDOWS\system32\BOOTVID.dll
0xB7F79000 ACPI.sys
0xB85AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xB7F68000 pci.sys
0xB80A8000 isapnp.sys
0xB80B8000 ohci1394.sys
0xB80C8000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
0xB84BC000 compbatt.sys
0xB84C0000 \WINDOWS\system32\DRIVERS\BATTC.SYS
0xB8670000 pciide.sys
0xB8328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xB85AC000 aliide.sys
0xB85AE000 cmdide.sys
0xB85B0000 toside.sys
0xB85B2000 viaide.sys
0xB85B4000 intelide.sys
0xB7F4A000 pcmcia.sys
0xB80D8000 MountMgr.sys
0xB7F2B000 ftdisk.sys
0xB8330000 PartMgr.sys
0xB84C4000 ACPIEC.sys
0xB8671000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
0xB80E8000 VolSnap.sys
0xB84C8000 cpqarray.sys
0xB7F13000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xB7D5E000 iaStor.sys
0xB7D46000 atapi.sys
0xB84CC000 aha154x.sys
0xB8338000 sparrow.sys
0xB84D0000 symc810.sys
0xB80F8000 aic78xx.sys
0xB84D4000 dac960nt.sys
0xB8108000 ql10wnt.sys
0xB84D8000 amsint.sys
0xB8340000 asc.sys
0xB84DC000 asc3550.sys
0xB8348000 mraid35x.sys
0xB8350000 i2omp.sys
0xB84E0000 ini910u.sys
0xB8118000 ql1240.sys
0xB8128000 aic78u2.sys
0xB8358000 symc8xx.sys
0xB8360000 sym_hi.sys
0xB8368000 sym_u3.sys
0xB8370000 ABP480N5.SYS
0xB8378000 asc3350p.sys
0xB85B6000 cd20xrnt.sys
0xB8138000 ultra.sys
0xB8380000 dpti2o.sys
0xB7D2D000 adpu160m.sys
0xB8148000 ql1080.sys
0xB8158000 ql1280.sys
0xB8168000 ql12160.sys
0xB7CF8000 KR10I.sys
0xB8388000 perc2.sys
0xB85B8000 perc2hib.sys
0xB8390000 hpn.sys
0xB84E4000 cbidf2k.sys
0xB7CCC000 dac2w2k.sys
0xB8178000 disk.sys
0xB8188000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xB7CAC000 fltMgr.sys
0xB7C9A000 sr.sys
0xB8198000 Lbd.sys
0xB81A8000 PxHelp20.sys
0xB7C83000 KSecDD.sys
0xB7BF6000 Ntfs.sys
0xB7BC9000 NDIS.sys
0xB81B8000 sisagp.sys
0xB81C8000 viaagp.sys
0xB84E8000 stdfltn.sys
0xB7BAF000 Mup.sys
0xB81D8000 agp440.sys
0xB81E8000 alim1541.sys
0xB81F8000 amdagp.sys
0xB8208000 agpCPQ.sys
0xB8228000 \SystemRoot\system32\DRIVERS\nic1394.sys
0xB4F54000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
0xB4F40000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xB4F18000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xB4EEE000 \SystemRoot\system32\DRIVERS\e1k5132.sys
0xB8400000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB4ECA000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xB4916000 \SystemRoot\system32\DRIVERS\NETw5x32.sys
0xB4905000 \SystemRoot\system32\DRIVERS\risdpe86.sys
0xB60A1000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xB8408000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xB48F1000 \SystemRoot\system32\DRIVERS\parport.sys
0xB48B2000 \SystemRoot\system32\DRIVERS\Apfiltr.sys
0xB6091000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS
0xB4841000 \SystemRoot\System32\Drivers\wdf01000.sys
0xB8410000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xB6081000 \SystemRoot\system32\DRIVERS\imapi.sys
0xB6071000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xB6061000 \SystemRoot\system32\DRIVERS\redbook.sys
0xB481E000 \SystemRoot\system32\DRIVERS\ks.sys
0xB47FD000 \SystemRoot\system32\DRIVERS\Impcd.sys
0xB6051000 \SystemRoot\system32\DRIVERS\Accelern.sys
0xB5BBB000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB7A42000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0xB7A3E000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0xB4720000 \SystemRoot\system32\DRIVERS\btkrnl.sys
0xB452D000 \SystemRoot\system32\DRIVERS\fw.sys
0xB5E77000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB5BAB000 \SystemRoot\system32\DRIVERS\dsNcAdpt.sys
0xB86C2000 \SystemRoot\system32\DRIVERS\audstub.sys
0xB5B9B000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xB7ADF000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB4516000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xB5B8B000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xB5B7B000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xB5E6F000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xB5E67000 \SystemRoot\system32\DRIVERS\raspti.sys
0xB44E6000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xB5B6B000 \SystemRoot\system32\DRIVERS\termdd.sys
0xB44C4000 \SystemRoot\system32\DRIVERS\teefer2.sys
0xB8620000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB27D7000 \SystemRoot\system32\DRIVERS\update.sys
0xB5711000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xB8298000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xB82C8000 \SystemRoot\system32\drivers\nvhda32.sys
0xB178B000 \SystemRoot\system32\drivers\portcls.sys
0xB82D8000 \SystemRoot\system32\drivers\drmk.sys
0xB1763000 \??\C:\WINDOWS\system32\Drivers\OA015Afx.sys
0xB60C1000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xB8630000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xB1596000 \SystemRoot\system32\drivers\sthda.sys
0xB157A000 \SystemRoot\system32\drivers\AESTAud.sys
0xB1552000 \??\C:\WINDOWS\system32\Drivers\CtAudDrv.sys
0xB7AB3000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0xB85E8000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xAE6DE000 \SystemRoot\System32\Drivers\Null.SYS
0xB83F8000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xB83B0000 \SystemRoot\System32\drivers\vga.sys
0xB85EA000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xB85EC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xB3930000 \SystemRoot\System32\Drivers\Msfs.SYS
0xB3928000 \SystemRoot\System32\Drivers\Npfs.SYS
0xB5715000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xAE530000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xB0635000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xAE4D7000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xB0625000 \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys
0xAE4B1000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xAE489000 \SystemRoot\system32\DRIVERS\netbt.sys
0xB0605000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xAE467000 \SystemRoot\System32\drivers\afd.sys
0xB05E5000 \SystemRoot\system32\DRIVERS\netbios.sys
0xAE7A8000 \SystemRoot\System32\Drivers\SRTSPX.SYS
0xAE3FD000 \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
0xAE798000 \SystemRoot\system32\DRIVERS\arp1394.sys
0xAE3D8000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
0xAA658000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xAA01F000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xAA5E7000 \SystemRoot\System32\Drivers\Fips.SYS
0xA9AB7000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xA9182000 \SystemRoot\system32\DRIVERS\OA015Vid.sys
0xA915E000 \SystemRoot\system32\DRIVERS\CtClsFlt.sys
0xA9E63000 \SystemRoot\System32\Drivers\btwusb.sys
0xA9E53000 \SystemRoot\System32\Drivers\cvusbdrv.sys
0xA98F0000 \SystemRoot\system32\DRIVERS\usbccid.sys
0xA9D45000 \SystemRoot\system32\DRIVERS\SMCLIB.SYS
0xA9100000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0xA90E3000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
0xA9D02000 \??\C:\Program Files\Dell\Reader 2.0\dvmio.sys
0xA90CF000 \SystemRoot\system32\DRIVERS\ctxusbm.sys
0xA98B0000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xA8F1A000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0xBF800000 \SystemRoot\System32\win32k.sys
0xA991A000 \SystemRoot\System32\drivers\Dxapi.sys
0xA97B5000 \SystemRoot\System32\watchdog.sys
0xBD000000 \SystemRoot\System32\drivers\dxg.sys
0xAE5B7000 \SystemRoot\System32\drivers\dxgthk.sys
0xBD012000 \SystemRoot\System32\nv4_disp.dll
0xBD5C8000 \SystemRoot\System32\ATMFD.DLL
0xAA55E000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xA6D08000 \??\C:\WINDOWS\system32\drivers\WpsHelper.sys
0xA6CF3000 \SystemRoot\system32\drivers\wdmaud.sys
0xAE62B000 \SystemRoot\system32\drivers\sysaudio.sys
0xA6C28000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xA6A3C000 \SystemRoot\System32\drivers\vpn.sys
0xA69E5000 \SystemRoot\system32\DRIVERS\srv.sys
0xB8428000 \SystemRoot\System32\DRIVERS\Scap.sys
0xA97AD000 \SystemRoot\System32\Drivers\TDTCP.SYS
0xA6332000 \SystemRoot\System32\Drivers\RDPWD.SYS
0xA5662000 \SystemRoot\System32\Drivers\HTTP.sys
0xA53E7000 \SystemRoot\System32\Drivers\SRTSP.SYS
0xA51F4000 \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20110331.003\NAVEX15.SYS
0xA51E0000 \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20110331.003\NAVENG.SYS
0xA441D000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll
Processes (total 67):
0 System Idle Process
4 System
1200 C:\WINDOWS\system32\smss.exe
1268 csrss.exe
1304 C:\WINDOWS\system32\winlogon.exe
1348 C:\WINDOWS\system32\services.exe
1384 C:\WINDOWS\system32\lsass.exe
1524 C:\WINDOWS\system32\nvsvc32.exe
1556 C:\WINDOWS\system32\svchost.exe
1644 svchost.exe
1684 C:\WINDOWS\system32\svchost.exe
1872 C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
1896 svchost.exe
1996 svchost.exe
484 C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
572 C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
768 C:\WINDOWS\system32\spoolsv.exe
812 C:\Drivers\MEDIA\STHDA_5.10.0.6261_B3992798038074661AD78E0FDD271A33\stacsv.exe
944 scardsvr.exe
1608 svchost.exe
1104 C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
1152 C:\Program Files\Dell\Reader 2.0\DVMExportService.exe
1176 C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe
1188 C:\Program Files\Java\jre6\bin\jqs.exe
1216 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
1264 C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
1724 C:\Program Files\SalesLogix\SLXSystem.exe
1068 C:\WINDOWS\system32\rundll32.exe
1764 C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
1800 C:\Program Files\CheckPoint\SecuRemote\bin\SR_Watchdog.exe
1816 C:\WINDOWS\system32\svchost.exe
1836 C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
2084 C:\Program Files\Marimba\Tuner\Tuner.exe
2128 C:\WINDOWS\system32\searchindexer.exe
2396 C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
2424 C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
2732 C:\WINDOWS\explorer.exe
2856 C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
3056 wmiprvse.exe
3228 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
3976 C:\Program Files\DellTPad\Apoint.exe
2540 C:\Program Files\DellTPad\ApMsgFwd.exe
2544 C:\WINDOWS\OA015Mon.exe
2552 C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
2992 C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
2996 C:\Program Files\DellTPad\hidfind.exe
3072 C:\Program Files\DellTPad\ApntEx.exe
3100 C:\Program Files\Dell\Reader 2.0\DellBtrEvent.exe
3116 C:\Program Files\Citrix\ICA Client\concentr.exe
3136 C:\WINDOWS\system32\wbem\unsecapp.exe
3240 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3292 C:\Program Files\Citrix\ICA Client\wfcrun32.exe
376 C:\WINDOWS\system32\ctfmon.exe
304 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
332 C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
2176 C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
2228 C:\Program Files\Windows Desktop Search\WindowsSearch.exe
3700 C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe
1044 unsecapp.exe
3600 alg.exe
3668 C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
3664 C:\WINDOWS\system32\searchprotocolhost.exe
5896 C:\Program Files\Internet Explorer\iexplore.exe
5748 C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
5508 searchfilterhost.exe
5972 C:\Program Files\Marimba\Tuner\lib\minituner.exe
492 C:\Documents and Settings\mark.phelps\Desktop\MBRCheck.exe
\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`007d8200 (NTFS)
PhysicalDrive0 Model Number: WDCWD1600BEKT-75A25T0, Rev: 01.01A01
Size Device Name MBR Status
——————————————–
149 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
Done!
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 21:45:40.50 on Thu 03/31/2011
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1162 [GMT -4:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Symantec Endpoint Protection *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
c:\drivers\media\sthda_5.10.0.6261_b3992798038074661ad78e0fdd271a33\stacsv.exe
svchost.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Dell\Reader 2.0\DVMExportService.exe
C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
C:\Program Files\SalesLogix\SLXSystem.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Marimba\Tuner\Tuner.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Marimba\Tuner\lib\jre\bin\java.exe
C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\WINDOWS\OA015Mon.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
C:\Program Files\Dell\Reader 2.0\DellBtrEvent.exe
C:\Program Files\Citrix\ICA Client\concentr.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Citrix\ICA Client\wfcrun32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Documents and Settings\mark.phelps\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [OA015Mon] c:\windows\OA015Mon.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [DellControlPoint] "c:\program files\dell\dell controlpoint\Dell.ControlPoint.exe"
mRun: [DellBtrEvent] c:\program files\dell\reader 2.0\DellBtrEvent.exe
mRun: [ConnectionCenter] "c:\program files\citrix\ica client\concentr.exe" /startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dellco~1.lnk - c:\program files\dell\dell controlpoint\system manager\DCPSysMgr.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Notify: ckpNotify - ckpNotify.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-3-30 64512]
R0 stdflt;Disk Filter Driver for Accelerometer;c:\windows\system32\drivers\stdfltn.sys [2011-1-5 17072]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [2010-7-14 65584]
R1 DVMIO;DVMIO;c:\program files\dell\reader 2.0\dvmio.sys [2010-2-1 18192]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\dell\dell controlpoint\DCPButtonSvc.exe [2009-11-20 278304]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2011-2-15 108392]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2011-2-15 108392]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\dell\dell controlpoint\system manager\DCPSysMgrSvc.exe [2010-2-8 376688]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\program files\dell\reader 2.0\DVMExportService.exe [2009-8-3 327680]
R2 InstallFilterService;FF Install Filter Service;c:\program files\stmicroelectronics\accelerometerp11\InstallFilterService.exe [2011-1-5 60928]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-3-30 1405384]
R2 risdpcie;risdpcie;c:\windows\system32\drivers\risdpe86.sys [2011-1-5 47616]
R2 SalesLogix System;SalesLogix System Service;c:\program files\saleslogix\SLXSystem.exe [2010-11-22 385024]
R2 Scap;SecureClient Application Policy Module;c:\windows\system32\drivers\scap.sys [2011-1-5 17456]
R2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec\symantec endpoint protection\Rtvscan.exe [2011-2-15 1831024]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [2011-1-5 670128]
R2 WKEndpoint;WK Endpoint;c:\program files\marimba\tuner\Tuner.exe [2010-1-19 36957]
R3 Acceler;Accelerometer Service;c:\windows\system32\drivers\Accelern.sys [2011-1-5 42672]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2011-1-5 113664]
R3 CtAudDrv;Provides advanced audio effects for audio devices.;c:\windows\system32\drivers\CtAudDrv.sys [2011-1-5 134144]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [2011-1-5 143968]
R3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [2011-1-5 33832]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [2011-1-5 167080]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-1-5 102448]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [2011-1-5 2041904]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2011-1-5 132480]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20110331.003\NAVENG.SYS [2011-3-31 86136]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20110331.003\NAVEX15.SYS [2011-3-31 1393144]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2011-1-5 58600]
R3 OA015Afx;Provides a software interface to control audio effects of OA015 camera.;c:\windows\system32\drivers\OA015Afx.sys [2011-1-5 134144]
R3 OA015Vid;Creative Camera OA015 Function Driver;c:\windows\system32\drivers\OA015Vid.sys [2011-1-5 273568]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys –> c:\windows\system32\drivers\is3srv.sys [?]
S0 szkg5;szkg5;c:\windows\system32\drivers\szkg.sys –> c:\windows\system32\drivers\szkg.sys [?]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys –> c:\windows\system32\drivers\szkgfs.sys [?]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2009-7-14 23888]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-3-30 15232]
S3 OMVA;VPN-1 SecureClient Adapter;c:\windows\system32\drivers\OMVA.sys [2011-1-5 14924]
.
=============== File Associations ===============
.
scrfile="%1" %*
.
=============== Created Last 30 ================
.
2011-03-30 17:15:52 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-03-30 17:09:48 ——– d—–w- c:\docume~1\alluse~1\applic~1\Applications
2011-03-30 15:31:38 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-03-30 15:31:16 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-03-30 15:28:10 ——– d—–w- c:\docume~1\mark~1.phe\locals~1\applic~1\Sunbelt Software
2011-03-30 15:20:12 ——– d—–w- c:\docume~1\mark~1.phe\locals~1\applic~1\Temp
2011-03-30 15:20:07 ——– d—–w- c:\docume~1\mark~1.phe\locals~1\applic~1\Google
2011-03-30 15:20:05 ——– dc-h–w- c:\docume~1\alluse~1\applic~1\{9937DA50-1322-492A-A1C8-1911CDD1BD57}
2011-03-30 15:19:53 ——– d—–w- c:\program files\Lavasoft
2011-03-30 15:13:59 ——– d—–w- c:\windows\system32\appmgmt
2011-03-30 14:07:03 ——– d—–w- c:\docume~1\alluse~1\applic~1\STOPzilla!
2011-03-26 02:57:29 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2011-03-26 02:57:29 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2011-03-26 01:27:33 135168 –sha-r- c:\windows\system32\nvrspll.dll
2011-03-16 12:29:03 ——– d—–w- c:\docume~1\mark~1.phe\applic~1\ElevatedDiagnostics
.
==================== Find3M ====================
.
2011-02-15 16:09:44 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2011-02-15 16:06:42 87368 —-a-w- c:\windows\system32\FwsVpn.dll
2011-02-15 16:06:42 107848 —-a-w- c:\windows\system32\SymVPN.dll
2011-02-09 13:53:52 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-05 17:25:34 82696 —-a-w- c:\windows\system32\lmdimon8.dll
2011-02-05 17:25:34 82184 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\lmdippr8.dll
2011-02-02 23:19:39 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58:35 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 —-a-w- c:\windows\system32\atmfd.dll
.
============= FINISH: 21:46:32.73 ===============
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-03-31 22:24:34
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD16 rev.01.0
Running: 2fpwlnbd.exe; Driver: C:\DOCUME~1\MARK~1.PHE\LOCALS~1\Temp\awryyaoc.sys
—- System - GMER 1.0.15 —-
SSDT 889C8680 ZwAlertResumeThread
SSDT 889AA5E0 ZwAlertThread
SSDT 889E25E8 ZwAllocateVirtualMemory
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xB819887E]
SSDT 88A27B18 ZwCreateMutant
SSDT 86B51580 ZwCreateThread
SSDT 889E1B20 ZwFreeVirtualMemory
SSDT 889BDCF0 ZwImpersonateAnonymousToken
SSDT 889BE6D8 ZwImpersonateThread
SSDT 88A100E8 ZwMapViewOfSection
SSDT 889BDA88 ZwOpenEvent
SSDT 88A04388 ZwOpenProcessToken
SSDT 889FF6E0 ZwOpenThreadToken
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation) ZwProtectVirtualMemory [0xB33D38B0]
SSDT 8895D158 ZwResumeThread
SSDT 88AEF8E0 ZwSetContextThread
SSDT 88A08750 ZwSetInformationProcess
SSDT 88A0F508 ZwSetInformationThread
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xB8198BFE]
SSDT 88A456C0 ZwSuspendProcess
SSDT 889AA908 ZwSuspendThread
SSDT 88475268 ZwTerminateProcess
SSDT 889B7AA8 ZwTerminateThread
SSDT 88AC3CD0 ZwUnmapViewOfSection
SSDT 889D5F98 ZwWriteVirtualMemory
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!ZwCallbackReturn + 2C28 805044C4 4 Bytes CALL 4AD8E2EE
.text ntkrnlpa.exe!ZwCallbackReturn + 2D94 80504630 4 Bytes CALL A2D8E735
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB5384380, 0x3E5D05, 0xE8000020]
init C:\WINDOWS\system32\Drivers\OA015Afx.sys entry point in "init" section [0xB1E58D50]
init C:\WINDOWS\system32\Drivers\CtAudDrv.sys entry point in "init" section [0xB1C47D50]
? C:\DOCUME~1\MARK~1.PHE\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] GDI32.dll!TextOutW 77F17EAC 5 Bytes JMP 0099C3B4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] GDI32.dll!ExtTextOutW 77F18086 5 Bytes JMP 0099C8EE
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] GDI32.dll!TextOutA 77F1BA4F 5 Bytes JMP 0099C2E7
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] GDI32.dll!ExtTextOutA 77F1D3FA 5 Bytes JMP 0099C809
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] GDI32.dll!GetGlyphIndicesA 77F3DFE3 5 Bytes JMP 0099CCA5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] GDI32.dll!GetGlyphIndicesW 77F52604 5 Bytes JMP 0099CD6F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E1DF4D9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DrawTextExW 7E42B415 5 Bytes JMP 0099C721
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DrawTextW 7E42D7E2 5 Bytes JMP 0099C55D
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!SetClipboardData 7E430F9E 5 Bytes JMP 0099C1D4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3527F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E352777 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3527BB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DrawTextA 7E43C702 5 Bytes JMP 0099C481
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DrawTextExA 7E43C739 5 Bytes JMP 0099C639
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E352703 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E35273D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E352831 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E20178A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3529F3 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 0099B3C6
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 0099C146
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!send 71AB4C27 5 Bytes JMP 0099BE2F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 0099C050
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 0099B309
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!recv 71AB676F 5 Bytes JMP 0099BED5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0099BF7F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[440] WS2_32.dll!WSAAsyncGetHostByName 71ABE99D 5 Bytes JMP 0099B75C
.text C:\WINDOWS\system32\SearchIndexer.exe[2520] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] GDI32.dll!TextOutW 77F17EAC 5 Bytes JMP 0092C3B4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] GDI32.dll!ExtTextOutW 77F18086 5 Bytes JMP 0092C8EE
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] GDI32.dll!TextOutA 77F1BA4F 5 Bytes JMP 0092C2E7
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] GDI32.dll!ExtTextOutA 77F1D3FA 5 Bytes JMP 0092C809
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] GDI32.dll!GetGlyphIndicesA 77F3DFE3 5 Bytes JMP 0092CCA5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] GDI32.dll!GetGlyphIndicesW 77F52604 5 Bytes JMP 0092CD6F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 0092B837
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DrawTextExW 7E42B415 5 Bytes JMP 0092C721
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DrawTextW 7E42D7E2 5 Bytes JMP 0092C55D
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!SetClipboardData 7E430F9E 5 Bytes JMP 0092C1D4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3527F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E352777 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3527BB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DrawTextA 7E43C702 5 Bytes JMP 0092C481
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DrawTextExA 7E43C739 5 Bytes JMP 0092C639
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E352703 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E35273D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E352831 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E20178A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3529F3 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 0092B3C6
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 0092C146
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!send 71AB4C27 5 Bytes JMP 0092BE2F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 0092C050
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 0092B309
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!recv 71AB676F 5 Bytes JMP 0092BED5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0092BF7F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2940] WS2_32.dll!WSAAsyncGetHostByName 71ABE99D 5 Bytes JMP 0092B75C
—- Devices - GMER 1.0.15 —-
Device \Driver\Tcpip \Device\Ip wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
Device \Driver\Tcpip \Device\Tcp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
Device \Driver\Tcpip \Device\Udp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
Device \Driver\Tcpip \Device\RawIp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
Device \Driver\Tcpip \Device\IPMULTICAST wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
—- EOF - GMER 1.0.15 —-
MBRCheck, version 1.2.3
© 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0004000c
Kernel Drivers (total 194):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E5000 \WINDOWS\system32\hal.dll
0xB85A8000 \WINDOWS\system32\KDCOM.DLL
0xB84B8000 \WINDOWS\system32\BOOTVID.dll
0xB7F79000 ACPI.sys
0xB85AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xB7F68000 pci.sys
0xB80A8000 isapnp.sys
0xB80B8000 ohci1394.sys
0xB80C8000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
0xB84BC000 compbatt.sys
0xB84C0000 \WINDOWS\system32\DRIVERS\BATTC.SYS
0xB8670000 pciide.sys
0xB8328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xB85AC000 aliide.sys
0xB85AE000 cmdide.sys
0xB85B0000 toside.sys
0xB85B2000 viaide.sys
0xB85B4000 intelide.sys
0xB7F4A000 pcmcia.sys
0xB80D8000 MountMgr.sys
0xB7F2B000 ftdisk.sys
0xB8330000 PartMgr.sys
0xB84C4000 ACPIEC.sys
0xB8671000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
0xB80E8000 VolSnap.sys
0xB84C8000 cpqarray.sys
0xB7F13000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xB7D5E000 iaStor.sys
0xB7D46000 atapi.sys
0xB84CC000 aha154x.sys
0xB8338000 sparrow.sys
0xB84D0000 symc810.sys
0xB80F8000 aic78xx.sys
0xB84D4000 dac960nt.sys
0xB8108000 ql10wnt.sys
0xB84D8000 amsint.sys
0xB8340000 asc.sys
0xB84DC000 asc3550.sys
0xB8348000 mraid35x.sys
0xB8350000 i2omp.sys
0xB84E0000 ini910u.sys
0xB8118000 ql1240.sys
0xB8128000 aic78u2.sys
0xB8358000 symc8xx.sys
0xB8360000 sym_hi.sys
0xB8368000 sym_u3.sys
0xB8370000 ABP480N5.SYS
0xB8378000 asc3350p.sys
0xB85B6000 cd20xrnt.sys
0xB8138000 ultra.sys
0xB8380000 dpti2o.sys
0xB7D2D000 adpu160m.sys
0xB8148000 ql1080.sys
0xB8158000 ql1280.sys
0xB8168000 ql12160.sys
0xB7CF8000 KR10I.sys
0xB8388000 perc2.sys
0xB85B8000 perc2hib.sys
0xB8390000 hpn.sys
0xB84E4000 cbidf2k.sys
0xB7CCC000 dac2w2k.sys
0xB8178000 disk.sys
0xB8188000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xB7CAC000 fltMgr.sys
0xB7C9A000 sr.sys
0xB8198000 Lbd.sys
0xB81A8000 PxHelp20.sys
0xB7C83000 KSecDD.sys
0xB7BF6000 Ntfs.sys
0xB7BC9000 NDIS.sys
0xB81B8000 sisagp.sys
0xB81C8000 viaagp.sys
0xB84E8000 stdfltn.sys
0xB7BAF000 Mup.sys
0xB81D8000 agp440.sys
0xB81E8000 alim1541.sys
0xB81F8000 amdagp.sys
0xB8208000 agpCPQ.sys
0xB8228000 \SystemRoot\system32\DRIVERS\nic1394.sys
0xB4F54000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
0xB4F40000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xB4F18000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xB4EEE000 \SystemRoot\system32\DRIVERS\e1k5132.sys
0xB8400000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB4ECA000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xB4916000 \SystemRoot\system32\DRIVERS\NETw5x32.sys
0xB4905000 \SystemRoot\system32\DRIVERS\risdpe86.sys
0xB60A1000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xB8408000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xB48F1000 \SystemRoot\system32\DRIVERS\parport.sys
0xB48B2000 \SystemRoot\system32\DRIVERS\Apfiltr.sys
0xB6091000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS
0xB4841000 \SystemRoot\System32\Drivers\wdf01000.sys
0xB8410000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xB6081000 \SystemRoot\system32\DRIVERS\imapi.sys
0xB6071000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xB6061000 \SystemRoot\system32\DRIVERS\redbook.sys
0xB481E000 \SystemRoot\system32\DRIVERS\ks.sys
0xB47FD000 \SystemRoot\system32\DRIVERS\Impcd.sys
0xB6051000 \SystemRoot\system32\DRIVERS\Accelern.sys
0xB5BBB000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB7A42000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0xB7A3E000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0xB4720000 \SystemRoot\system32\DRIVERS\btkrnl.sys
0xB452D000 \SystemRoot\system32\DRIVERS\fw.sys
0xB5E77000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB5BAB000 \SystemRoot\system32\DRIVERS\dsNcAdpt.sys
0xB86C2000 \SystemRoot\system32\DRIVERS\audstub.sys
0xB5B9B000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xB7ADF000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB4516000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xB5B8B000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xB5B7B000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xB5E6F000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xB5E67000 \SystemRoot\system32\DRIVERS\raspti.sys
0xB44E6000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xB5B6B000 \SystemRoot\system32\DRIVERS\termdd.sys
0xB44C4000 \SystemRoot\system32\DRIVERS\teefer2.sys
0xB8620000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB27D7000 \SystemRoot\system32\DRIVERS\update.sys
0xB5711000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xB8298000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xB82C8000 \SystemRoot\system32\drivers\nvhda32.sys
0xB178B000 \SystemRoot\system32\drivers\portcls.sys
0xB82D8000 \SystemRoot\system32\drivers\drmk.sys
0xB1763000 \??\C:\WINDOWS\system32\Drivers\OA015Afx.sys
0xB60C1000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xB8630000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xB1596000 \SystemRoot\system32\drivers\sthda.sys
0xB157A000 \SystemRoot\system32\drivers\AESTAud.sys
0xB1552000 \??\C:\WINDOWS\system32\Drivers\CtAudDrv.sys
0xB7AB3000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0xB85E8000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xAE6DE000 \SystemRoot\System32\Drivers\Null.SYS
0xB83F8000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xB83B0000 \SystemRoot\System32\drivers\vga.sys
0xB85EA000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xB85EC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xB3930000 \SystemRoot\System32\Drivers\Msfs.SYS
0xB3928000 \SystemRoot\System32\Drivers\Npfs.SYS
0xB5715000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xAE530000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xB0635000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xAE4D7000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xB0625000 \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys
0xAE4B1000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xAE489000 \SystemRoot\system32\DRIVERS\netbt.sys
0xB0605000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xAE467000 \SystemRoot\System32\drivers\afd.sys
0xB05E5000 \SystemRoot\system32\DRIVERS\netbios.sys
0xAE7A8000 \SystemRoot\System32\Drivers\SRTSPX.SYS
0xAE3FD000 \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
0xAE798000 \SystemRoot\system32\DRIVERS\arp1394.sys
0xAE3D8000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
0xAA658000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xAA01F000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xAA5E7000 \SystemRoot\System32\Drivers\Fips.SYS
0xA9AB7000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xA9182000 \SystemRoot\system32\DRIVERS\OA015Vid.sys
0xA915E000 \SystemRoot\system32\DRIVERS\CtClsFlt.sys
0xA9E63000 \SystemRoot\System32\Drivers\btwusb.sys
0xA9E53000 \SystemRoot\System32\Drivers\cvusbdrv.sys
0xA98F0000 \SystemRoot\system32\DRIVERS\usbccid.sys
0xA9D45000 \SystemRoot\system32\DRIVERS\SMCLIB.SYS
0xA9100000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0xA90E3000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
0xA9D02000 \??\C:\Program Files\Dell\Reader 2.0\dvmio.sys
0xA90CF000 \SystemRoot\system32\DRIVERS\ctxusbm.sys
0xA98B0000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xA8F1A000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0xBF800000 \SystemRoot\System32\win32k.sys
0xA991A000 \SystemRoot\System32\drivers\Dxapi.sys
0xA97B5000 \SystemRoot\System32\watchdog.sys
0xBD000000 \SystemRoot\System32\drivers\dxg.sys
0xAE5B7000 \SystemRoot\System32\drivers\dxgthk.sys
0xBD012000 \SystemRoot\System32\nv4_disp.dll
0xBD5C8000 \SystemRoot\System32\ATMFD.DLL
0xAA55E000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xA6D08000 \??\C:\WINDOWS\system32\drivers\WpsHelper.sys
0xA6CF3000 \SystemRoot\system32\drivers\wdmaud.sys
0xAE62B000 \SystemRoot\system32\drivers\sysaudio.sys
0xA6C28000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xA6A3C000 \SystemRoot\System32\drivers\vpn.sys
0xA69E5000 \SystemRoot\system32\DRIVERS\srv.sys
0xB8428000 \SystemRoot\System32\DRIVERS\Scap.sys
0xA97AD000 \SystemRoot\System32\Drivers\TDTCP.SYS
0xA6332000 \SystemRoot\System32\Drivers\RDPWD.SYS
0xA5662000 \SystemRoot\System32\Drivers\HTTP.sys
0xA53E7000 \SystemRoot\System32\Drivers\SRTSP.SYS
0xA51F4000 \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20110331.003\NAVEX15.SYS
0xA51E0000 \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20110331.003\NAVENG.SYS
0xA441D000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll
Processes (total 67):
0 System Idle Process
4 System
1200 C:\WINDOWS\system32\smss.exe
1268 csrss.exe
1304 C:\WINDOWS\system32\winlogon.exe
1348 C:\WINDOWS\system32\services.exe
1384 C:\WINDOWS\system32\lsass.exe
1524 C:\WINDOWS\system32\nvsvc32.exe
1556 C:\WINDOWS\system32\svchost.exe
1644 svchost.exe
1684 C:\WINDOWS\system32\svchost.exe
1872 C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
1896 svchost.exe
1996 svchost.exe
484 C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
572 C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
768 C:\WINDOWS\system32\spoolsv.exe
812 C:\Drivers\MEDIA\STHDA_5.10.0.6261_B3992798038074661AD78E0FDD271A33\stacsv.exe
944 scardsvr.exe
1608 svchost.exe
1104 C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
1152 C:\Program Files\Dell\Reader 2.0\DVMExportService.exe
1176 C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe
1188 C:\Program Files\Java\jre6\bin\jqs.exe
1216 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
1264 C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
1724 C:\Program Files\SalesLogix\SLXSystem.exe
1068 C:\WINDOWS\system32\rundll32.exe
1764 C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
1800 C:\Program Files\CheckPoint\SecuRemote\bin\SR_Watchdog.exe
1816 C:\WINDOWS\system32\svchost.exe
1836 C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
2084 C:\Program Files\Marimba\Tuner\Tuner.exe
2128 C:\WINDOWS\system32\searchindexer.exe
2396 C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
2424 C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
2732 C:\WINDOWS\explorer.exe
2856 C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
3056 wmiprvse.exe
3228 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
3976 C:\Program Files\DellTPad\Apoint.exe
2540 C:\Program Files\DellTPad\ApMsgFwd.exe
2544 C:\WINDOWS\OA015Mon.exe
2552 C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
2992 C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
2996 C:\Program Files\DellTPad\hidfind.exe
3072 C:\Program Files\DellTPad\ApntEx.exe
3100 C:\Program Files\Dell\Reader 2.0\DellBtrEvent.exe
3116 C:\Program Files\Citrix\ICA Client\concentr.exe
3136 C:\WINDOWS\system32\wbem\unsecapp.exe
3240 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3292 C:\Program Files\Citrix\ICA Client\wfcrun32.exe
376 C:\WINDOWS\system32\ctfmon.exe
304 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
332 C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
2176 C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
2228 C:\Program Files\Windows Desktop Search\WindowsSearch.exe
3700 C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe
1044 unsecapp.exe
3600 alg.exe
3668 C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
3664 C:\WINDOWS\system32\searchprotocolhost.exe
5896 C:\Program Files\Internet Explorer\iexplore.exe
5748 C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
5508 searchfilterhost.exe
5972 C:\Program Files\Marimba\Tuner\lib\minituner.exe
492 C:\Documents and Settings\mark.phelps\Desktop\MBRCheck.exe
\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`007d8200 (NTFS)
PhysicalDrive0 Model Number: WDCWD1600BEKT-75A25T0, Rev: 01.01A01
Size Device Name MBR Status
——————————————–
149 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
Done!
Blottedisk
Hi mrmarky,
Follow these steps:
Step 1 | Please double-click My Computer.
Step 2 | Please go to the following site to scan a file: Virus Total
Follow these steps:
Step 1 | Please double-click My Computer.
- Click the Tools menu, and then click Folder Options.
- Click the View tab.
- Uncheck "Hide file extensions for known file types."
- Under the "Hidden files" folder, select "Show hidden files and folders."
- Uncheck "Hide protected operating system files."
- Click Apply, and then click OK.
Step 2 | Please go to the following site to scan a file: Virus Total
- Click on Browse, and upload the following file for analysis:
- c:\windows\OA015Mon.exe
c:\windows\system32\drivers\OA015Afx.sys
c:\windows\system32\drivers\OA015Vid.sys
c:\windows\system32\nvrspll.dll
- c:\windows\OA015Mon.exe
- Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
- If it says already scanned – click "reanalyze now"
- Please post the results in your next reply.
mrmarky
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: OA015Mon.exe
Submission date: 2011-04-01 12:58:05 (UTC)
Current status: queued (#1) queued (#1) analysing finished
Result: 0/ 42 (0.0%)
VT Community
not reviewed
Safety score: -
Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.04.01.01 2011.04.01 -
AntiVir 7.11.5.161 2011.04.01 -
Antiy-AVL 2.0.3.7 2011.03.31 -
Avast 4.8.1351.0 2011.04.01 -
Avast5 5.0.677.0 2011.04.01 -
AVG 10.0.0.1190 2011.04.01 -
BitDefender 7.2 2011.04.01 -
CAT-QuickHeal 11.00 2011.04.01 -
ClamAV 0.97.0.0 2011.04.01 -
Commtouch 5.2.11.5 2011.03.24 -
Comodo 8183 2011.04.01 -
DrWeb 5.0.2.03300 2011.04.01 -
Emsisoft 5.1.0.5 2011.04.01 -
eSafe 7.0.17.0 2011.04.01 -
eTrust-Vet 36.1.8247 2011.04.01 -
F-Prot 4.6.2.117 2011.04.01 -
F-Secure 9.0.16440.0 2011.03.23 -
Fortinet 4.2.254.0 2011.04.01 -
GData 22 2011.04.01 -
Ikarus T3.1.1.103.0 2011.04.01 -
Jiangmin 13.0.900 2011.03.31 -
K7AntiVirus 9.96.4269 2011.04.01 -
Kaspersky 7.0.0.125 2011.04.01 -
McAfee 5.400.0.1158 2011.04.01 -
McAfee-GW-Edition 2010.1C 2011.04.01 -
Microsoft 1.6702 2011.04.01 -
NOD32 6005 2011.04.01 -
Norman 6.07.03 2011.04.01 -
Panda 10.0.3.5 2011.03.31 -
PCTools 7.0.3.5 2011.04.01 -
Prevx 3.0 2011.04.01 -
Rising 23.51.03.06 2011.03.31 -
Sophos 4.64.0 2011.04.01 -
SUPERAntiSpyware 4.40.0.1006 2011.04.01 -
Symantec 20101.3.2.89 2011.04.01 -
TheHacker 6.7.0.1.164 2011.04.01 -
TrendMicro 9.200.0.1012 2011.04.01 -
TrendMicro-HouseCall 9.200.0.1012 2011.04.01 -
VBA32 3.12.14.3 2011.03.31 -
VIPRE 8885 2011.04.01 -
ViRobot 2011.4.1.4388 2011.04.01 -
VirusBuster 13.6.280.0 2011.03.31 -
Additional informationShow all
MD5 : fe53d4313879ae2e27cfa899b3033071
SHA1 : a0d2e5c8c774d9104fea8386090424b658aa0246
SHA256: 82e2f13786d27e7d776cc6d254245832f84f7ba683e862f567071209777517c0
File name: OA015Afx.sys
Submission date: 2011-04-01 13:24:58 (UTC)
Current status: queued queued analysing finished
Result: 0/ 42 (0.0%)
VT Community
not reviewed
Safety score: -
Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.04.01.01 2011.04.01 -
AntiVir 7.11.5.161 2011.04.01 -
Antiy-AVL 2.0.3.7 2011.03.31 -
Avast 4.8.1351.0 2011.04.01 -
Avast5 5.0.677.0 2011.04.01 -
AVG 10.0.0.1190 2011.04.01 -
BitDefender 7.2 2011.04.01 -
CAT-QuickHeal 11.00 2011.04.01 -
ClamAV 0.97.0.0 2011.04.01 -
Commtouch 5.2.11.5 2011.03.24 -
Comodo 8183 2011.04.01 -
DrWeb 5.0.2.03300 2011.04.01 -
Emsisoft 5.1.0.5 2011.04.01 -
eSafe 7.0.17.0 2011.04.01 -
eTrust-Vet 36.1.8247 2011.04.01 -
F-Prot 4.6.2.117 2011.04.01 -
F-Secure 9.0.16440.0 2011.04.01 -
Fortinet 4.2.254.0 2011.04.01 -
GData 22 2011.04.01 -
Ikarus T3.1.1.103.0 2011.04.01 -
Jiangmin 13.0.900 2011.03.31 -
K7AntiVirus 9.96.4269 2011.04.01 -
Kaspersky 7.0.0.125 2011.04.01 -
McAfee 5.400.0.1158 2011.04.01 -
McAfee-GW-Edition 2010.1C 2011.04.01 -
Microsoft 1.6702 2011.04.01 -
NOD32 6005 2011.04.01 -
Norman 6.07.03 2011.04.01 -
Panda 10.0.3.5 2011.03.31 -
PCTools 7.0.3.5 2011.04.01 -
Prevx 3.0 2011.04.01 -
Rising 23.51.03.06 2011.03.31 -
Sophos 4.64.0 2011.04.01 -
SUPERAntiSpyware 4.40.0.1006 2011.04.01 -
Symantec 20101.3.2.89 2011.04.01 -
TheHacker 6.7.0.1.164 2011.04.01 -
TrendMicro 9.200.0.1012 2011.04.01 -
TrendMicro-HouseCall 9.200.0.1012 2011.04.01 -
VBA32 3.12.14.3 2011.03.31 -
VIPRE 8885 2011.04.01 -
ViRobot 2011.4.1.4388 2011.04.01 -
VirusBuster 13.6.280.0 2011.03.31 -
Additional informationShow all
MD5 : 0f538df1673e5216f3baacb6911d9d0f
SHA1 : bf6e55b339e220d141ba5e448d1d3cb8623cfc69
SHA256: 640a0ba1f897e7f927a01e44408202ef4884d2fe68e4ccb185f315d2b6f2e262
File name: OA015Vid.sys
Submission date: 2011-04-01 13:27:06 (UTC)
Current status: queued (#4) queued analysing finished
Result: 0/ 40 (0.0%)
VT Community
not reviewed
Safety score: -
Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.04.01.01 2011.04.01 -
AntiVir 7.11.5.161 2011.04.01 -
Antiy-AVL 2.0.3.7 2011.03.31 -
Avast 4.8.1351.0 2011.04.01 -
Avast5 5.0.677.0 2011.04.01 -
AVG 10.0.0.1190 2011.04.01 -
BitDefender 7.2 2011.04.01 -
CAT-QuickHeal 11.00 2011.04.01 -
ClamAV 0.97.0.0 2011.04.01 -
Commtouch 5.2.11.5 2011.03.24 -
Comodo 8183 2011.04.01 -
DrWeb 5.0.2.03300 2011.04.01 -
eSafe 7.0.17.0 2011.04.01 -
eTrust-Vet 36.1.8247 2011.04.01 -
F-Prot 4.6.2.117 2011.04.01 -
F-Secure 9.0.16440.0 2011.04.01 -
Fortinet 4.2.254.0 2011.04.01 -
GData 22 2011.04.01 -
Ikarus T3.1.1.103.0 2011.04.01 -
Jiangmin 13.0.900 2011.03.31 -
K7AntiVirus 9.96.4269 2011.04.01 -
McAfee 5.400.0.1158 2011.04.01 -
McAfee-GW-Edition 2010.1C 2011.04.01 -
Microsoft 1.6702 2011.04.01 -
NOD32 6005 2011.04.01 -
Norman 6.07.03 2011.04.01 -
Panda 10.0.3.5 2011.03.31 -
PCTools 7.0.3.5 2011.04.01 -
Prevx 3.0 2011.04.01 -
Rising 23.51.03.06 2011.03.31 -
Sophos 4.64.0 2011.04.01 -
SUPERAntiSpyware 4.40.0.1006 2011.04.01 -
Symantec 20101.3.2.89 2011.04.01 -
TheHacker 6.7.0.1.164 2011.04.01 -
TrendMicro 9.200.0.1012 2011.04.01 -
TrendMicro-HouseCall 9.200.0.1012 2011.04.01 -
VBA32 3.12.14.3 2011.03.31 -
VIPRE 8885 2011.04.01 -
ViRobot 2011.4.1.4388 2011.04.01 -
VirusBuster 13.6.280.0 2011.03.31 -
Additional informationShow all
MD5 : 1a4a57d16df0b6a48ba117eaf913a22f
SHA1 : fffe61985dd669923d780cf8b367c92038fbd296
SHA256: fadc9b282888b84d92e58a3c9bdd538214bac9a2522661fd1f41480a19a94743
c:\windows\system32\nvrspll.dll didn't give me a log after it ran.
Blottedisk
Hi mrmarky,
Thanks for the logs. Please visit the following and have a look how you can disable your security software.
How to disable your security programs
After disabling your security programs, download Combofix from any of the links below and save it to your desktop.
Link 1
Link 2
——————————————————————–
If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Thanks for the logs. Please visit the following and have a look how you can disable your security software.
How to disable your security programs
After disabling your security programs, download Combofix from any of the links below and save it to your desktop.
Link 1
Link 2
——————————————————————–
- Double click on Combofix.exe & follow the prompts.
- When finished, it will produce a report for you.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
[external image: Posted Image]
- Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
- Click on Yes, to continue scanning for malware.
- When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.
If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
mrmarky
ComboFix 11-03-31.05 - Mark.Phelps 04/01/2011 11:12:57.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1058 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Symantec Endpoint Protection *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *Disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\sqlite3.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-03-01 to 2011-04-01 )))))))))))))))))))))))))))))))
.
.
2011-03-30 17:15 . 2011-03-30 17:15 ——– d—–w- c:\program files\Common Files\Java
2011-03-30 17:15 . 2011-02-03 01:40 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-03-30 17:09 . 2011-03-30 17:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Applications
2011-03-30 15:31 . 2011-03-30 07:15 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-03-30 15:31 . 2011-03-30 15:31 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-03-30 15:28 . 2011-03-30 15:28 ——– d—–w- c:\documents and settings\mark.phelps\Local Settings\Application Data\Sunbelt Software
2011-03-30 15:25 . 2011-03-30 15:25 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2011-03-30 15:20 . 2011-03-30 15:20 ——– d—–w- c:\documents and settings\mark.phelps\Local Settings\Application Data\Temp
2011-03-30 15:20 . 2011-03-30 15:20 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-03-30 15:20 . 2011-03-30 17:08 ——– d—–w- c:\documents and settings\mark.phelps\Local Settings\Application Data\Google
2011-03-30 15:20 . 2011-03-30 15:20 ——– d—–w- c:\program files\Google
2011-03-30 15:20 . 2011-03-30 15:20 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{9937DA50-1322-492A-A1C8-1911CDD1BD57}
2011-03-30 15:19 . 2011-03-30 15:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2011-03-30 15:19 . 2011-03-30 15:19 ——– d—–w- c:\program files\Lavasoft
2011-03-30 14:07 . 2011-03-30 15:13 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2011-03-26 02:57 . 2008-04-14 04:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2011-03-26 02:57 . 2008-04-14 04:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2011-03-26 01:27 . 2011-03-26 01:27 135168 –sha-r- c:\windows\system32\nvrspll.dll
2011-03-16 12:29 . 2011-03-16 12:29 ——– d—–w- c:\documents and settings\mark.phelps\Application Data\ElevatedDiagnostics
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-15 16:09 . 2010-04-27 19:44 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2011-02-15 16:09 . 2010-04-27 19:44 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-02-15 16:06 . 2011-02-15 16:06 67472 —-a-w- c:\windows\system32\drivers\Teefer2.sys
2011-02-15 16:06 . 2011-02-15 16:06 87368 —-a-w- c:\windows\system32\FwsVpn.dll
2011-02-15 16:06 . 2011-02-15 16:06 43336 —-a-w- c:\windows\system32\drivers\WPSDRVnt.sys
2011-02-15 16:06 . 2011-02-15 16:06 107848 —-a-w- c:\windows\system32\SymVPN.dll
2011-02-15 16:06 . 2011-02-15 16:06 43696 —-a-w- c:\windows\system32\drivers\srtspx.sys
2011-02-15 16:06 . 2011-02-15 16:06 320944 —-a-w- c:\windows\system32\drivers\srtspl.sys
2011-02-15 16:06 . 2011-02-15 16:06 283184 —-a-w- c:\windows\system32\drivers\srtsp.sys
2011-02-09 13:53 . 2010-04-27 22:21 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2010-04-27 22:21 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-05 17:25 . 2010-04-27 20:37 82696 —-a-w- c:\windows\system32\lmdimon8.dll
2011-02-05 17:25 . 2010-04-27 20:37 82184 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\lmdippr8.dll
2011-02-02 23:19 . 2010-04-27 20:18 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58 . 2010-04-27 19:31 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2010-04-27 19:31 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2010-04-27 22:21 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2010-04-27 22:21 290048 —-a-w- c:\windows\system32\atmfd.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2011-02-15 115560]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-05-12 278528]
"OA015Mon"="c:\windows\OA015Mon.exe" [2010-05-12 24576]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-04-02 128232]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2009-11-02 657920]
"DellBtrEvent"="c:\program files\Dell\Reader 2.0\DellBtrEvent.exe" [2009-08-26 147456]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-10-12 304568]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-02-19 13803520]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-2-25 636256]
Dell ControlPoint System Manager.lnk - c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe [2010-2-8 1338224]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
2005-03-02 00:49 24672 —-a-w- c:\windows\system32\ckpNotify.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%programfiles%\\AR System\\alert.exe"=
"%programfiles%\\AR System\\aruser.exe"=
"%programfiles%\\Remedy\\aruser.exe"=
"%programfiles%\\Checkpoint\\SecurRemote\\bin\\SR_GUI.exe"= %programfiles%\\Checkpoint\\SecuRemote\\bin\\SR_GUI.exe
"%programfiles%\\Citrix\\ICA Client\\pn.exe"=
"%programfiles%\\e!pc\\extra.exe"=
"%programfiles%\\Hummingbird\\Connectivity\\7.00\\Exceed\\exceed.exe"=
"%programfiles%\\Hummingbird\\Connectivity\\8.00\\Exceed\\exceed.exe"=
"%programfiles%\\VERITAS\\Backup Exec\\NT\\beserver.exe"=
"%programfiles%\\Netmeeting\\conf.exe"=
"%programfiles%\\IBM\\OnDemand32\\ODClient.exe"=
"%programfiles%\\Symantec\\pcAnywhere\\awhost32.exe"=
"%programfiles%\\Symantec\\pcAnywhere\\winaw32.exe"=
"%programfiles%\\Symantec\\pcAnywhere\\awrem32.exe"=
"%programfiles%\\Reflection\\r1win.exe"=
"%programfiles%\\Reflection\\r2win.exe"=
"%windir%\\dmremote.exe"=
"%programfiles%\\Messenger\\msmsgs.exe"=
"%programfiles%\\WinSCP3\\WinSCP.exe"= %programfiles%\\WinSCP3\\WinSCP3.exe
"%programfiles%\\Yahoo!\\Messenger\\ypager.exe"=
"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\program files\\marimba\\tuner\\lib\\jre\\bin\\java.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"21:TCP"= 21:TCP:FTP (TCP 21)
"21:UDP"= 21:UDP:FTP (UDP 21)
"23:TCP"= 23:TCP:TELNET (TCP 23)
"23:UDP"= 23:UDP:TELNET (UDP 23)
"5282:TCP"= 5282:TCP:MARIMBA (TCP 5282)
"5282:UDP"= 5282:UDP:MARIMBA (UDP 5282)
"7717:TCP"= 7717:TCP:MARIMBA (TCP 7717)
"7717:UDP"= 7717:UDP:MARIMBA (UDP 7717)
"8888:TCP"= 8888:TCP:MARIMBA (TCP 8888)
"8888:UDP"= 8888:UDP:MARIMBA (UDP 8888)
"1433:TCP"= 1433:TCP:SQL (TCP 1433)
"1433:UDP"= 1433:UDP:SQL (UDP 1433)
"3389:TCP"= 3389:TCP:Remote Desktop (TCP)
"3389:UDP"= 3389:UDP:Remote Desktop (UDP)
"139:TCP"= 139:TCP:File and Printer Sharing
"445:TCP"= 445:TCP:File and Printer Sharing
"137:UDP"= 137:UDP:File and Printer Sharing
"138:UDP"= 138:UDP:File and Printer Sharing
"2967:TCP"= 2967:TCP:10.204.34.100,10.204.34.101,10.204.34.102,10.200.34.101,10.200.34.102:e
nabled:Symantec AntiVirus
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/30/2011 11:31 AM 64512]
R0 stdflt;Disk Filter Driver for Accelerometer;c:\windows\system32\drivers\stdfltn.sys [1/5/2011 3:27 PM 17072]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [7/14/2010 1:51 PM 65584]
R1 DVMIO;DVMIO;c:\program files\Dell\Reader 2.0\dvmio.sys [2/1/2010 6:11 PM 18192]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [11/20/2009 6:42 PM 278304]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe [2/8/2010 5:20 PM 376688]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\program files\Dell\Reader 2.0\DVMExportService.exe [8/3/2009 3:35 PM 327680]
R2 risdpcie;risdpcie;c:\windows\system32\drivers\risdpe86.sys [1/5/2011 6:53 PM 47616]
R2 SalesLogix System;SalesLogix System Service;c:\program files\SalesLogix\SLXSystem.exe [11/22/2010 8:53 AM 385024]
R2 Scap;SecureClient Application Policy Module;c:\windows\system32\drivers\scap.sys [1/5/2011 6:12 PM 17456]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [1/5/2011 6:12 PM 670128]
R2 WKEndpoint;WK Endpoint;c:\program files\Marimba\Tuner\Tuner.exe [1/19/2010 10:00 AM 36957]
R3 Acceler;Accelerometer Service;c:\windows\system32\drivers\Accelern.sys [1/5/2011 3:27 PM 42672]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [1/5/2011 6:53 PM 113664]
R3 CtAudDrv;Provides advanced audio effects for audio devices.;c:\windows\system32\drivers\CtAudDrv.sys [1/5/2011 3:22 PM 134144]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [1/5/2011 3:22 PM 143968]
R3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [1/5/2011 6:53 PM 33832]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [1/5/2011 6:53 PM 167080]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [1/5/2011 3:24 PM 102448]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [1/5/2011 6:12 PM 2041904]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [1/5/2011 6:53 PM 132480]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [3/30/2011 3:15 AM 15232]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [1/5/2011 6:53 PM 58600]
R3 OA015Afx;Provides a software interface to control audio effects of OA015 camera.;c:\windows\system32\drivers\OA015Afx.sys [1/5/2011 6:53 PM 134144]
R3 OA015Vid;Creative Camera OA015 Function Driver;c:\windows\system32\drivers\OA015Vid.sys [1/5/2011 6:53 PM 273568]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys –> c:\windows\system32\drivers\is3srv.sys [?]
S0 szkg5;szkg5;c:\windows\system32\DRIVERS\szkg.sys –> c:\windows\system32\DRIVERS\szkg.sys [?]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys –> c:\windows\system32\drivers\szkgfs.sys [?]
S2 InstallFilterService;FF Install Filter Service;c:\program files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe [1/5/2011 3:27 PM 60928]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/30/2011 3:15 AM 1405384]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [7/14/2009 1:51 PM 23888]
S3 OMVA;VPN-1 SecureClient Adapter;c:\windows\system32\drivers\OMVA.sys [1/5/2011 6:12 PM 14924]
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-03-30 07:15]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath -
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-Symantec Antvirus
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-01 11:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-04-01 11:19:00
ComboFix-quarantined-files.txt 2011-04-01 15:18
.
Pre-Run: 142,862,524,416 bytes free
Post-Run: 143,103,496,192 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
.
- - End Of File - - 31BFAC2DA3379DC4BAC5C02C6A0116EE
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1058 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Symantec Endpoint Protection *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *Disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\sqlite3.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-03-01 to 2011-04-01 )))))))))))))))))))))))))))))))
.
.
2011-03-30 17:15 . 2011-03-30 17:15 ——– d—–w- c:\program files\Common Files\Java
2011-03-30 17:15 . 2011-02-03 01:40 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-03-30 17:09 . 2011-03-30 17:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Applications
2011-03-30 15:31 . 2011-03-30 07:15 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-03-30 15:31 . 2011-03-30 15:31 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-03-30 15:28 . 2011-03-30 15:28 ——– d—–w- c:\documents and settings\mark.phelps\Local Settings\Application Data\Sunbelt Software
2011-03-30 15:25 . 2011-03-30 15:25 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2011-03-30 15:20 . 2011-03-30 15:20 ——– d—–w- c:\documents and settings\mark.phelps\Local Settings\Application Data\Temp
2011-03-30 15:20 . 2011-03-30 15:20 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-03-30 15:20 . 2011-03-30 17:08 ——– d—–w- c:\documents and settings\mark.phelps\Local Settings\Application Data\Google
2011-03-30 15:20 . 2011-03-30 15:20 ——– d—–w- c:\program files\Google
2011-03-30 15:20 . 2011-03-30 15:20 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{9937DA50-1322-492A-A1C8-1911CDD1BD57}
2011-03-30 15:19 . 2011-03-30 15:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2011-03-30 15:19 . 2011-03-30 15:19 ——– d—–w- c:\program files\Lavasoft
2011-03-30 14:07 . 2011-03-30 15:13 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2011-03-26 02:57 . 2008-04-14 04:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2011-03-26 02:57 . 2008-04-14 04:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2011-03-26 01:27 . 2011-03-26 01:27 135168 –sha-r- c:\windows\system32\nvrspll.dll
2011-03-16 12:29 . 2011-03-16 12:29 ——– d—–w- c:\documents and settings\mark.phelps\Application Data\ElevatedDiagnostics
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-15 16:09 . 2010-04-27 19:44 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2011-02-15 16:09 . 2010-04-27 19:44 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-02-15 16:06 . 2011-02-15 16:06 67472 —-a-w- c:\windows\system32\drivers\Teefer2.sys
2011-02-15 16:06 . 2011-02-15 16:06 87368 —-a-w- c:\windows\system32\FwsVpn.dll
2011-02-15 16:06 . 2011-02-15 16:06 43336 —-a-w- c:\windows\system32\drivers\WPSDRVnt.sys
2011-02-15 16:06 . 2011-02-15 16:06 107848 —-a-w- c:\windows\system32\SymVPN.dll
2011-02-15 16:06 . 2011-02-15 16:06 43696 —-a-w- c:\windows\system32\drivers\srtspx.sys
2011-02-15 16:06 . 2011-02-15 16:06 320944 —-a-w- c:\windows\system32\drivers\srtspl.sys
2011-02-15 16:06 . 2011-02-15 16:06 283184 —-a-w- c:\windows\system32\drivers\srtsp.sys
2011-02-09 13:53 . 2010-04-27 22:21 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2010-04-27 22:21 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-05 17:25 . 2010-04-27 20:37 82696 —-a-w- c:\windows\system32\lmdimon8.dll
2011-02-05 17:25 . 2010-04-27 20:37 82184 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\lmdippr8.dll
2011-02-02 23:19 . 2010-04-27 20:18 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58 . 2010-04-27 19:31 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2010-04-27 19:31 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2010-04-27 22:21 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2010-04-27 22:21 290048 —-a-w- c:\windows\system32\atmfd.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2011-02-15 115560]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-05-12 278528]
"OA015Mon"="c:\windows\OA015Mon.exe" [2010-05-12 24576]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-04-02 128232]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2009-11-02 657920]
"DellBtrEvent"="c:\program files\Dell\Reader 2.0\DellBtrEvent.exe" [2009-08-26 147456]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-10-12 304568]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-02-19 13803520]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-2-25 636256]
Dell ControlPoint System Manager.lnk - c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe [2010-2-8 1338224]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
2005-03-02 00:49 24672 —-a-w- c:\windows\system32\ckpNotify.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%programfiles%\\AR System\\alert.exe"=
"%programfiles%\\AR System\\aruser.exe"=
"%programfiles%\\Remedy\\aruser.exe"=
"%programfiles%\\Checkpoint\\SecurRemote\\bin\\SR_GUI.exe"= %programfiles%\\Checkpoint\\SecuRemote\\bin\\SR_GUI.exe
"%programfiles%\\Citrix\\ICA Client\\pn.exe"=
"%programfiles%\\e!pc\\extra.exe"=
"%programfiles%\\Hummingbird\\Connectivity\\7.00\\Exceed\\exceed.exe"=
"%programfiles%\\Hummingbird\\Connectivity\\8.00\\Exceed\\exceed.exe"=
"%programfiles%\\VERITAS\\Backup Exec\\NT\\beserver.exe"=
"%programfiles%\\Netmeeting\\conf.exe"=
"%programfiles%\\IBM\\OnDemand32\\ODClient.exe"=
"%programfiles%\\Symantec\\pcAnywhere\\awhost32.exe"=
"%programfiles%\\Symantec\\pcAnywhere\\winaw32.exe"=
"%programfiles%\\Symantec\\pcAnywhere\\awrem32.exe"=
"%programfiles%\\Reflection\\r1win.exe"=
"%programfiles%\\Reflection\\r2win.exe"=
"%windir%\\dmremote.exe"=
"%programfiles%\\Messenger\\msmsgs.exe"=
"%programfiles%\\WinSCP3\\WinSCP.exe"= %programfiles%\\WinSCP3\\WinSCP3.exe
"%programfiles%\\Yahoo!\\Messenger\\ypager.exe"=
"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\program files\\marimba\\tuner\\lib\\jre\\bin\\java.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"21:TCP"= 21:TCP:FTP (TCP 21)
"21:UDP"= 21:UDP:FTP (UDP 21)
"23:TCP"= 23:TCP:TELNET (TCP 23)
"23:UDP"= 23:UDP:TELNET (UDP 23)
"5282:TCP"= 5282:TCP:MARIMBA (TCP 5282)
"5282:UDP"= 5282:UDP:MARIMBA (UDP 5282)
"7717:TCP"= 7717:TCP:MARIMBA (TCP 7717)
"7717:UDP"= 7717:UDP:MARIMBA (UDP 7717)
"8888:TCP"= 8888:TCP:MARIMBA (TCP 8888)
"8888:UDP"= 8888:UDP:MARIMBA (UDP 8888)
"1433:TCP"= 1433:TCP:SQL (TCP 1433)
"1433:UDP"= 1433:UDP:SQL (UDP 1433)
"3389:TCP"= 3389:TCP:Remote Desktop (TCP)
"3389:UDP"= 3389:UDP:Remote Desktop (UDP)
"139:TCP"= 139:TCP:File and Printer Sharing
"445:TCP"= 445:TCP:File and Printer Sharing
"137:UDP"= 137:UDP:File and Printer Sharing
"138:UDP"= 138:UDP:File and Printer Sharing
"2967:TCP"= 2967:TCP:10.204.34.100,10.204.34.101,10.204.34.102,10.200.34.101,10.200.34.102:e
nabled:Symantec AntiVirus
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/30/2011 11:31 AM 64512]
R0 stdflt;Disk Filter Driver for Accelerometer;c:\windows\system32\drivers\stdfltn.sys [1/5/2011 3:27 PM 17072]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [7/14/2010 1:51 PM 65584]
R1 DVMIO;DVMIO;c:\program files\Dell\Reader 2.0\dvmio.sys [2/1/2010 6:11 PM 18192]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [11/20/2009 6:42 PM 278304]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe [2/8/2010 5:20 PM 376688]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\program files\Dell\Reader 2.0\DVMExportService.exe [8/3/2009 3:35 PM 327680]
R2 risdpcie;risdpcie;c:\windows\system32\drivers\risdpe86.sys [1/5/2011 6:53 PM 47616]
R2 SalesLogix System;SalesLogix System Service;c:\program files\SalesLogix\SLXSystem.exe [11/22/2010 8:53 AM 385024]
R2 Scap;SecureClient Application Policy Module;c:\windows\system32\drivers\scap.sys [1/5/2011 6:12 PM 17456]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [1/5/2011 6:12 PM 670128]
R2 WKEndpoint;WK Endpoint;c:\program files\Marimba\Tuner\Tuner.exe [1/19/2010 10:00 AM 36957]
R3 Acceler;Accelerometer Service;c:\windows\system32\drivers\Accelern.sys [1/5/2011 3:27 PM 42672]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [1/5/2011 6:53 PM 113664]
R3 CtAudDrv;Provides advanced audio effects for audio devices.;c:\windows\system32\drivers\CtAudDrv.sys [1/5/2011 3:22 PM 134144]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [1/5/2011 3:22 PM 143968]
R3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [1/5/2011 6:53 PM 33832]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [1/5/2011 6:53 PM 167080]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [1/5/2011 3:24 PM 102448]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [1/5/2011 6:12 PM 2041904]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [1/5/2011 6:53 PM 132480]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [3/30/2011 3:15 AM 15232]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [1/5/2011 6:53 PM 58600]
R3 OA015Afx;Provides a software interface to control audio effects of OA015 camera.;c:\windows\system32\drivers\OA015Afx.sys [1/5/2011 6:53 PM 134144]
R3 OA015Vid;Creative Camera OA015 Function Driver;c:\windows\system32\drivers\OA015Vid.sys [1/5/2011 6:53 PM 273568]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys –> c:\windows\system32\drivers\is3srv.sys [?]
S0 szkg5;szkg5;c:\windows\system32\DRIVERS\szkg.sys –> c:\windows\system32\DRIVERS\szkg.sys [?]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys –> c:\windows\system32\drivers\szkgfs.sys [?]
S2 InstallFilterService;FF Install Filter Service;c:\program files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe [1/5/2011 3:27 PM 60928]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/30/2011 3:15 AM 1405384]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [7/14/2009 1:51 PM 23888]
S3 OMVA;VPN-1 SecureClient Adapter;c:\windows\system32\drivers\OMVA.sys [1/5/2011 6:12 PM 14924]
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-03-30 07:15]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath -
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-Symantec Antvirus
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-01 11:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-04-01 11:19:00
ComboFix-quarantined-files.txt 2011-04-01 15:18
.
Pre-Run: 142,862,524,416 bytes free
Post-Run: 143,103,496,192 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
.
- - End Of File - - 31BFAC2DA3379DC4BAC5C02C6A0116EE
mrmarky
Also, after running combofix, none of my internet shortcuts work.
Blottedisk
Hi mrmarky,
C:\Program Files\Internet Explorer
Double-click the file iexplore.exe. Does Internet Explorer open now?
One question: do you purposely have these firewall ports open?
"21:TCP"= 21:TCP:FTP (TCP 21)
"21:UDP"= 21:UDP:FTP (UDP 21)
"23:TCP"= 23:TCP:TELNET (TCP 23)
"23:UDP"= 23:UDP:TELNET (UDP 23)
"5282:TCP"= 5282:TCP:MARIMBA (TCP 5282)
"5282:UDP"= 5282:UDP:MARIMBA (UDP 5282)
"7717:TCP"= 7717:TCP:MARIMBA (TCP 7717)
"7717:UDP"= 7717:UDP:MARIMBA (UDP 7717)
"8888:TCP"= 8888:TCP:MARIMBA (TCP 8888)
"8888:UDP"= 8888:UDP:MARIMBA (UDP 8888)
"1433:TCP"= 1433:TCP:SQL (TCP 1433)
"1433:UDP"= 1433:UDP:SQL (UDP 1433)
"3389:TCP"= 3389:TCP:Remote Desktop (TCP)
"3389:UDP"= 3389:UDP:Remote Desktop (UDP)
"139:TCP"= 139:TCP:File and Printer Sharing
"445:TCP"= 445:TCP:File and Printer Sharing
"137:UDP"= 137:UDP:File and Printer Sharing
"138:UDP"= 138:UDP:File and Printer Sharing
Ok, let's proceed with Combofix. Please close any open browsers. Disable your antivirus and antispyware applications, usually via a right-click on the System Tray icon. They may otherwise interfere with ComboFix.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
[external image: Posted Image]
**Note: When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis. Ensure you are connected to the internet and click OK on the message box.
Was the submission successful?
Please post back including the Combofix log.
Please go to the following location:Also, after running combofix, none of my internet shortcuts work.
C:\Program Files\Internet Explorer
Double-click the file iexplore.exe. Does Internet Explorer open now?
One question: do you purposely have these firewall ports open?
"21:TCP"= 21:TCP:FTP (TCP 21)
"21:UDP"= 21:UDP:FTP (UDP 21)
"23:TCP"= 23:TCP:TELNET (TCP 23)
"23:UDP"= 23:UDP:TELNET (UDP 23)
"5282:TCP"= 5282:TCP:MARIMBA (TCP 5282)
"5282:UDP"= 5282:UDP:MARIMBA (UDP 5282)
"7717:TCP"= 7717:TCP:MARIMBA (TCP 7717)
"7717:UDP"= 7717:UDP:MARIMBA (UDP 7717)
"8888:TCP"= 8888:TCP:MARIMBA (TCP 8888)
"8888:UDP"= 8888:UDP:MARIMBA (UDP 8888)
"1433:TCP"= 1433:TCP:SQL (TCP 1433)
"1433:UDP"= 1433:UDP:SQL (UDP 1433)
"3389:TCP"= 3389:TCP:Remote Desktop (TCP)
"3389:UDP"= 3389:UDP:Remote Desktop (UDP)
"139:TCP"= 139:TCP:File and Printer Sharing
"445:TCP"= 445:TCP:File and Printer Sharing
"137:UDP"= 137:UDP:File and Printer Sharing
"138:UDP"= 138:UDP:File and Printer Sharing
Ok, let's proceed with Combofix. Please close any open browsers. Disable your antivirus and antispyware applications, usually via a right-click on the System Tray icon. They may otherwise interfere with ComboFix.
- Please open Notepad.
- In Notepad, Click "Format" and be certain that Word Wrap is not checked.
- Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE:
http://forums.whatthetech.com/index.php?showtopic=117843 Collect:: c:\windows\system32\nvrspll.dll
- In the notepad click File, Save as…, and set the Save in to your Desktop
- In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
- Click save.
- Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.
- This will start ComboFix again.Close all browser/windows first.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
[external image: Posted Image]
**Note: When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis. Ensure you are connected to the internet and click OK on the message box.
Was the submission successful?
Please post back including the Combofix log.
mrmarky
ComboFix 11-03-31.05 - Mark.Phelps 04/01/2011 13:53:30.2.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1267 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mark.phelps\Desktop\CFScript.txt
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Symantec Endpoint Protection *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *Disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
.
file zipped: c:\windows\system32\nvrspll.dll
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\nvrspll.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-03-01 to 2011-04-01 )))))))))))))))))))))))))))))))
.
.
2011-03-30 17:15 . 2011-03-30 17:15 ——– d—–w- c:\program files\Common Files\Java
2011-03-30 17:15 . 2011-02-03 01:40 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-03-30 17:09 . 2011-03-30 17:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Applications
2011-03-30 15:31 . 2011-03-30 07:15 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-03-30 15:31 . 2011-03-30 15:31 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-03-30 15:28 . 2011-03-30 15:28 ——– d—–w- c:\documents and settings\mark.phelps\Local Settings\Application Data\Sunbelt Software
2011-03-30 15:25 . 2011-03-30 15:25 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2011-03-30 15:20 . 2011-03-30 15:20 ——– d—–w- c:\documents and settings\mark.phelps\Local Settings\Application Data\Temp
2011-03-30 15:20 . 2011-03-30 15:20 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-03-30 15:20 . 2011-03-30 17:08 ——– d—–w- c:\documents and settings\mark.phelps\Local Settings\Application Data\Google
2011-03-30 15:20 . 2011-03-30 15:20 ——– d—–w- c:\program files\Google
2011-03-30 15:20 . 2011-03-30 15:20 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{9937DA50-1322-492A-A1C8-1911CDD1BD57}
2011-03-30 15:19 . 2011-03-30 15:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2011-03-30 15:19 . 2011-03-30 15:19 ——– d—–w- c:\program files\Lavasoft
2011-03-30 14:07 . 2011-03-30 15:13 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2011-03-26 02:57 . 2008-04-14 04:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2011-03-26 02:57 . 2008-04-14 04:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2011-03-16 12:29 . 2011-03-16 12:29 ——– d—–w- c:\documents and settings\mark.phelps\Application Data\ElevatedDiagnostics
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-15 16:09 . 2010-04-27 19:44 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2011-02-15 16:09 . 2010-04-27 19:44 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-02-15 16:06 . 2011-02-15 16:06 67472 —-a-w- c:\windows\system32\drivers\Teefer2.sys
2011-02-15 16:06 . 2011-02-15 16:06 87368 —-a-w- c:\windows\system32\FwsVpn.dll
2011-02-15 16:06 . 2011-02-15 16:06 43336 —-a-w- c:\windows\system32\drivers\WPSDRVnt.sys
2011-02-15 16:06 . 2011-02-15 16:06 107848 —-a-w- c:\windows\system32\SymVPN.dll
2011-02-15 16:06 . 2011-02-15 16:06 43696 —-a-w- c:\windows\system32\drivers\srtspx.sys
2011-02-15 16:06 . 2011-02-15 16:06 320944 —-a-w- c:\windows\system32\drivers\srtspl.sys
2011-02-15 16:06 . 2011-02-15 16:06 283184 —-a-w- c:\windows\system32\drivers\srtsp.sys
2011-02-09 13:53 . 2010-04-27 22:21 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2010-04-27 22:21 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-05 17:25 . 2010-04-27 20:37 82696 —-a-w- c:\windows\system32\lmdimon8.dll
2011-02-05 17:25 . 2010-04-27 20:37 82184 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\lmdippr8.dll
2011-02-02 23:19 . 2010-04-27 20:18 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58 . 2010-04-27 19:31 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2010-04-27 19:31 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2010-04-27 22:21 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2010-04-27 22:21 290048 —-a-w- c:\windows\system32\atmfd.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-04-01_15.17.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-01 17:58 . 2011-04-01 17:58 16384 c:\windows\Temp\Perflib_Perfdata_66c.dat
+ 2011-01-05 19:09 . 2011-04-01 17:03 153501 c:\windows\system32\nvModes.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2011-02-15 115560]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-05-12 278528]
"OA015Mon"="c:\windows\OA015Mon.exe" [2010-05-12 24576]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-04-02 128232]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2009-11-02 657920]
"DellBtrEvent"="c:\program files\Dell\Reader 2.0\DellBtrEvent.exe" [2009-08-26 147456]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-10-12 304568]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-02-19 13803520]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-2-25 636256]
Dell ControlPoint System Manager.lnk - c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe [2010-2-8 1338224]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
2005-03-02 00:49 24672 —-a-w- c:\windows\system32\ckpNotify.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%programfiles%\\AR System\\alert.exe"=
"%programfiles%\\AR System\\aruser.exe"=
"%programfiles%\\Remedy\\aruser.exe"=
"%programfiles%\\Checkpoint\\SecurRemote\\bin\\SR_GUI.exe"= %programfiles%\\Checkpoint\\SecuRemote\\bin\\SR_GUI.exe
"%programfiles%\\Citrix\\ICA Client\\pn.exe"=
"%programfiles%\\e!pc\\extra.exe"=
"%programfiles%\\Hummingbird\\Connectivity\\7.00\\Exceed\\exceed.exe"=
"%programfiles%\\Hummingbird\\Connectivity\\8.00\\Exceed\\exceed.exe"=
"%programfiles%\\VERITAS\\Backup Exec\\NT\\beserver.exe"=
"%programfiles%\\Netmeeting\\conf.exe"=
"%programfiles%\\IBM\\OnDemand32\\ODClient.exe"=
"%programfiles%\\Symantec\\pcAnywhere\\awhost32.exe"=
"%programfiles%\\Symantec\\pcAnywhere\\winaw32.exe"=
"%programfiles%\\Symantec\\pcAnywhere\\awrem32.exe"=
"%programfiles%\\Reflection\\r1win.exe"=
"%programfiles%\\Reflection\\r2win.exe"=
"%windir%\\dmremote.exe"=
"%programfiles%\\Messenger\\msmsgs.exe"=
"%programfiles%\\WinSCP3\\WinSCP.exe"= %programfiles%\\WinSCP3\\WinSCP3.exe
"%programfiles%\\Yahoo!\\Messenger\\ypager.exe"=
"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\program files\\marimba\\tuner\\lib\\jre\\bin\\java.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"21:TCP"= 21:TCP:FTP (TCP 21)
"21:UDP"= 21:UDP:FTP (UDP 21)
"23:TCP"= 23:TCP:TELNET (TCP 23)
"23:UDP"= 23:UDP:TELNET (UDP 23)
"5282:TCP"= 5282:TCP:MARIMBA (TCP 5282)
"5282:UDP"= 5282:UDP:MARIMBA (UDP 5282)
"7717:TCP"= 7717:TCP:MARIMBA (TCP 7717)
"7717:UDP"= 7717:UDP:MARIMBA (UDP 7717)
"8888:TCP"= 8888:TCP:MARIMBA (TCP 8888)
"8888:UDP"= 8888:UDP:MARIMBA (UDP 8888)
"1433:TCP"= 1433:TCP:SQL (TCP 1433)
"1433:UDP"= 1433:UDP:SQL (UDP 1433)
"3389:TCP"= 3389:TCP:Remote Desktop (TCP)
"3389:UDP"= 3389:UDP:Remote Desktop (UDP)
"139:TCP"= 139:TCP:File and Printer Sharing
"445:TCP"= 445:TCP:File and Printer Sharing
"137:UDP"= 137:UDP:File and Printer Sharing
"138:UDP"= 138:UDP:File and Printer Sharing
"2967:TCP"= 2967:TCP:10.204.34.100,10.204.34.101,10.204.34.102,10.200.34.101,10.200.34.102:e
nabled:Symantec AntiVirus
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/30/2011 11:31 AM 64512]
R0 stdflt;Disk Filter Driver for Accelerometer;c:\windows\system32\drivers\stdfltn.sys [1/5/2011 3:27 PM 17072]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [7/14/2010 1:51 PM 65584]
R1 DVMIO;DVMIO;c:\program files\Dell\Reader 2.0\dvmio.sys [2/1/2010 6:11 PM 18192]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [11/20/2009 6:42 PM 278304]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe [2/8/2010 5:20 PM 376688]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\program files\Dell\Reader 2.0\DVMExportService.exe [8/3/2009 3:35 PM 327680]
R2 InstallFilterService;FF Install Filter Service;c:\program files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe [1/5/2011 3:27 PM 60928]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/30/2011 3:15 AM 1405384]
R2 risdpcie;risdpcie;c:\windows\system32\drivers\risdpe86.sys [1/5/2011 6:53 PM 47616]
R2 SalesLogix System;SalesLogix System Service;c:\program files\SalesLogix\SLXSystem.exe [11/22/2010 8:53 AM 385024]
R2 Scap;SecureClient Application Policy Module;c:\windows\system32\drivers\scap.sys [1/5/2011 6:12 PM 17456]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [1/5/2011 6:12 PM 670128]
R2 WKEndpoint;WK Endpoint;c:\program files\Marimba\Tuner\Tuner.exe [1/19/2010 10:00 AM 36957]
R3 Acceler;Accelerometer Service;c:\windows\system32\drivers\Accelern.sys [1/5/2011 3:27 PM 42672]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [1/5/2011 6:53 PM 113664]
R3 CtAudDrv;Provides advanced audio effects for audio devices.;c:\windows\system32\drivers\CtAudDrv.sys [1/5/2011 3:22 PM 134144]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [1/5/2011 3:22 PM 143968]
R3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [1/5/2011 6:53 PM 33832]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [1/5/2011 6:53 PM 167080]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [1/5/2011 3:24 PM 102448]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [1/5/2011 6:12 PM 2041904]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [1/5/2011 6:53 PM 132480]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [1/5/2011 6:53 PM 58600]
R3 OA015Afx;Provides a software interface to control audio effects of OA015 camera.;c:\windows\system32\drivers\OA015Afx.sys [1/5/2011 6:53 PM 134144]
R3 OA015Vid;Creative Camera OA015 Function Driver;c:\windows\system32\drivers\OA015Vid.sys [1/5/2011 6:53 PM 273568]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys –> c:\windows\system32\drivers\is3srv.sys [?]
S0 szkg5;szkg5;c:\windows\system32\DRIVERS\szkg.sys –> c:\windows\system32\DRIVERS\szkg.sys [?]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys –> c:\windows\system32\drivers\szkgfs.sys [?]
S3 CFcatchme;CFcatchme;\??\c:\docume~1\MARK~1.PHE\LOCALS~1\Temp\CFcatchme.sys –> c:\docume~1\MARK~1.PHE\LOCALS~1\Temp\CFcatchme.sys [?]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [7/14/2009 1:51 PM 23888]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [3/30/2011 3:15 AM 15232]
S3 OMVA;VPN-1 SecureClient Adapter;c:\windows\system32\drivers\OMVA.sys [1/5/2011 6:12 PM 14924]
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-03-30 07:15]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-01 14:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(4900)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvsvc32.exe
c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\drivers\media\sthda_5.10.0.6261_b3992798038074661ad78e0fdd271a33\stacsv.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Neoteris\Installer Service\NeoterisSetupService.exe
c:\program files\CheckPoint\SecuRemote\bin\SR_Service.exe
c:\program files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Citrix\ICA Client\wfcrun32.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\Marimba\Tuner\lib\minituner.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2011-04-01 14:04:41 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-01 18:04
ComboFix2.txt 2011-04-01 15:19
.
Pre-Run: 143,102,574,592 bytes free
Post-Run: 143,088,553,984 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - AD8630DA9BF53E0DAB020BB1105DC294
Upload was successful
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1267 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mark.phelps\Desktop\CFScript.txt
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Symantec Endpoint Protection *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *Disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
.
file zipped: c:\windows\system32\nvrspll.dll
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\nvrspll.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-03-01 to 2011-04-01 )))))))))))))))))))))))))))))))
.
.
2011-03-30 17:15 . 2011-03-30 17:15 ——– d—–w- c:\program files\Common Files\Java
2011-03-30 17:15 . 2011-02-03 01:40 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-03-30 17:09 . 2011-03-30 17:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Applications
2011-03-30 15:31 . 2011-03-30 07:15 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-03-30 15:31 . 2011-03-30 15:31 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-03-30 15:28 . 2011-03-30 15:28 ——– d—–w- c:\documents and settings\mark.phelps\Local Settings\Application Data\Sunbelt Software
2011-03-30 15:25 . 2011-03-30 15:25 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2011-03-30 15:20 . 2011-03-30 15:20 ——– d—–w- c:\documents and settings\mark.phelps\Local Settings\Application Data\Temp
2011-03-30 15:20 . 2011-03-30 15:20 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-03-30 15:20 . 2011-03-30 17:08 ——– d—–w- c:\documents and settings\mark.phelps\Local Settings\Application Data\Google
2011-03-30 15:20 . 2011-03-30 15:20 ——– d—–w- c:\program files\Google
2011-03-30 15:20 . 2011-03-30 15:20 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{9937DA50-1322-492A-A1C8-1911CDD1BD57}
2011-03-30 15:19 . 2011-03-30 15:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2011-03-30 15:19 . 2011-03-30 15:19 ——– d—–w- c:\program files\Lavasoft
2011-03-30 14:07 . 2011-03-30 15:13 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2011-03-26 02:57 . 2008-04-14 04:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2011-03-26 02:57 . 2008-04-14 04:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2011-03-16 12:29 . 2011-03-16 12:29 ——– d—–w- c:\documents and settings\mark.phelps\Application Data\ElevatedDiagnostics
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-15 16:09 . 2010-04-27 19:44 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2011-02-15 16:09 . 2010-04-27 19:44 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-02-15 16:06 . 2011-02-15 16:06 67472 —-a-w- c:\windows\system32\drivers\Teefer2.sys
2011-02-15 16:06 . 2011-02-15 16:06 87368 —-a-w- c:\windows\system32\FwsVpn.dll
2011-02-15 16:06 . 2011-02-15 16:06 43336 —-a-w- c:\windows\system32\drivers\WPSDRVnt.sys
2011-02-15 16:06 . 2011-02-15 16:06 107848 —-a-w- c:\windows\system32\SymVPN.dll
2011-02-15 16:06 . 2011-02-15 16:06 43696 —-a-w- c:\windows\system32\drivers\srtspx.sys
2011-02-15 16:06 . 2011-02-15 16:06 320944 —-a-w- c:\windows\system32\drivers\srtspl.sys
2011-02-15 16:06 . 2011-02-15 16:06 283184 —-a-w- c:\windows\system32\drivers\srtsp.sys
2011-02-09 13:53 . 2010-04-27 22:21 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2010-04-27 22:21 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-05 17:25 . 2010-04-27 20:37 82696 —-a-w- c:\windows\system32\lmdimon8.dll
2011-02-05 17:25 . 2010-04-27 20:37 82184 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\lmdippr8.dll
2011-02-02 23:19 . 2010-04-27 20:18 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58 . 2010-04-27 19:31 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2010-04-27 19:31 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2010-04-27 22:21 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2010-04-27 22:21 290048 —-a-w- c:\windows\system32\atmfd.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-04-01_15.17.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-01 17:58 . 2011-04-01 17:58 16384 c:\windows\Temp\Perflib_Perfdata_66c.dat
+ 2011-01-05 19:09 . 2011-04-01 17:03 153501 c:\windows\system32\nvModes.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2011-02-15 115560]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-05-12 278528]
"OA015Mon"="c:\windows\OA015Mon.exe" [2010-05-12 24576]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-04-02 128232]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2009-11-02 657920]
"DellBtrEvent"="c:\program files\Dell\Reader 2.0\DellBtrEvent.exe" [2009-08-26 147456]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-10-12 304568]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-02-19 13803520]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-2-25 636256]
Dell ControlPoint System Manager.lnk - c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe [2010-2-8 1338224]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
2005-03-02 00:49 24672 —-a-w- c:\windows\system32\ckpNotify.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%programfiles%\\AR System\\alert.exe"=
"%programfiles%\\AR System\\aruser.exe"=
"%programfiles%\\Remedy\\aruser.exe"=
"%programfiles%\\Checkpoint\\SecurRemote\\bin\\SR_GUI.exe"= %programfiles%\\Checkpoint\\SecuRemote\\bin\\SR_GUI.exe
"%programfiles%\\Citrix\\ICA Client\\pn.exe"=
"%programfiles%\\e!pc\\extra.exe"=
"%programfiles%\\Hummingbird\\Connectivity\\7.00\\Exceed\\exceed.exe"=
"%programfiles%\\Hummingbird\\Connectivity\\8.00\\Exceed\\exceed.exe"=
"%programfiles%\\VERITAS\\Backup Exec\\NT\\beserver.exe"=
"%programfiles%\\Netmeeting\\conf.exe"=
"%programfiles%\\IBM\\OnDemand32\\ODClient.exe"=
"%programfiles%\\Symantec\\pcAnywhere\\awhost32.exe"=
"%programfiles%\\Symantec\\pcAnywhere\\winaw32.exe"=
"%programfiles%\\Symantec\\pcAnywhere\\awrem32.exe"=
"%programfiles%\\Reflection\\r1win.exe"=
"%programfiles%\\Reflection\\r2win.exe"=
"%windir%\\dmremote.exe"=
"%programfiles%\\Messenger\\msmsgs.exe"=
"%programfiles%\\WinSCP3\\WinSCP.exe"= %programfiles%\\WinSCP3\\WinSCP3.exe
"%programfiles%\\Yahoo!\\Messenger\\ypager.exe"=
"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\program files\\marimba\\tuner\\lib\\jre\\bin\\java.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"21:TCP"= 21:TCP:FTP (TCP 21)
"21:UDP"= 21:UDP:FTP (UDP 21)
"23:TCP"= 23:TCP:TELNET (TCP 23)
"23:UDP"= 23:UDP:TELNET (UDP 23)
"5282:TCP"= 5282:TCP:MARIMBA (TCP 5282)
"5282:UDP"= 5282:UDP:MARIMBA (UDP 5282)
"7717:TCP"= 7717:TCP:MARIMBA (TCP 7717)
"7717:UDP"= 7717:UDP:MARIMBA (UDP 7717)
"8888:TCP"= 8888:TCP:MARIMBA (TCP 8888)
"8888:UDP"= 8888:UDP:MARIMBA (UDP 8888)
"1433:TCP"= 1433:TCP:SQL (TCP 1433)
"1433:UDP"= 1433:UDP:SQL (UDP 1433)
"3389:TCP"= 3389:TCP:Remote Desktop (TCP)
"3389:UDP"= 3389:UDP:Remote Desktop (UDP)
"139:TCP"= 139:TCP:File and Printer Sharing
"445:TCP"= 445:TCP:File and Printer Sharing
"137:UDP"= 137:UDP:File and Printer Sharing
"138:UDP"= 138:UDP:File and Printer Sharing
"2967:TCP"= 2967:TCP:10.204.34.100,10.204.34.101,10.204.34.102,10.200.34.101,10.200.34.102:e
nabled:Symantec AntiVirus
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/30/2011 11:31 AM 64512]
R0 stdflt;Disk Filter Driver for Accelerometer;c:\windows\system32\drivers\stdfltn.sys [1/5/2011 3:27 PM 17072]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [7/14/2010 1:51 PM 65584]
R1 DVMIO;DVMIO;c:\program files\Dell\Reader 2.0\dvmio.sys [2/1/2010 6:11 PM 18192]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [11/20/2009 6:42 PM 278304]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe [2/8/2010 5:20 PM 376688]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\program files\Dell\Reader 2.0\DVMExportService.exe [8/3/2009 3:35 PM 327680]
R2 InstallFilterService;FF Install Filter Service;c:\program files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe [1/5/2011 3:27 PM 60928]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/30/2011 3:15 AM 1405384]
R2 risdpcie;risdpcie;c:\windows\system32\drivers\risdpe86.sys [1/5/2011 6:53 PM 47616]
R2 SalesLogix System;SalesLogix System Service;c:\program files\SalesLogix\SLXSystem.exe [11/22/2010 8:53 AM 385024]
R2 Scap;SecureClient Application Policy Module;c:\windows\system32\drivers\scap.sys [1/5/2011 6:12 PM 17456]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [1/5/2011 6:12 PM 670128]
R2 WKEndpoint;WK Endpoint;c:\program files\Marimba\Tuner\Tuner.exe [1/19/2010 10:00 AM 36957]
R3 Acceler;Accelerometer Service;c:\windows\system32\drivers\Accelern.sys [1/5/2011 3:27 PM 42672]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [1/5/2011 6:53 PM 113664]
R3 CtAudDrv;Provides advanced audio effects for audio devices.;c:\windows\system32\drivers\CtAudDrv.sys [1/5/2011 3:22 PM 134144]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [1/5/2011 3:22 PM 143968]
R3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [1/5/2011 6:53 PM 33832]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [1/5/2011 6:53 PM 167080]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [1/5/2011 3:24 PM 102448]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [1/5/2011 6:12 PM 2041904]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [1/5/2011 6:53 PM 132480]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [1/5/2011 6:53 PM 58600]
R3 OA015Afx;Provides a software interface to control audio effects of OA015 camera.;c:\windows\system32\drivers\OA015Afx.sys [1/5/2011 6:53 PM 134144]
R3 OA015Vid;Creative Camera OA015 Function Driver;c:\windows\system32\drivers\OA015Vid.sys [1/5/2011 6:53 PM 273568]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys –> c:\windows\system32\drivers\is3srv.sys [?]
S0 szkg5;szkg5;c:\windows\system32\DRIVERS\szkg.sys –> c:\windows\system32\DRIVERS\szkg.sys [?]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys –> c:\windows\system32\drivers\szkgfs.sys [?]
S3 CFcatchme;CFcatchme;\??\c:\docume~1\MARK~1.PHE\LOCALS~1\Temp\CFcatchme.sys –> c:\docume~1\MARK~1.PHE\LOCALS~1\Temp\CFcatchme.sys [?]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [7/14/2009 1:51 PM 23888]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [3/30/2011 3:15 AM 15232]
S3 OMVA;VPN-1 SecureClient Adapter;c:\windows\system32\drivers\OMVA.sys [1/5/2011 6:12 PM 14924]
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-03-30 07:15]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-01 14:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(4900)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvsvc32.exe
c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\drivers\media\sthda_5.10.0.6261_b3992798038074661ad78e0fdd271a33\stacsv.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Neoteris\Installer Service\NeoterisSetupService.exe
c:\program files\CheckPoint\SecuRemote\bin\SR_Service.exe
c:\program files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Citrix\ICA Client\wfcrun32.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\Marimba\Tuner\lib\minituner.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2011-04-01 14:04:41 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-01 18:04
ComboFix2.txt 2011-04-01 15:19
.
Pre-Run: 143,102,574,592 bytes free
Post-Run: 143,088,553,984 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - AD8630DA9BF53E0DAB020BB1105DC294
Upload was successful
Blottedisk
Please download and run the Following tool: http://noahdfear.net/downloads/HAMeb_check.exe
Once the tool has completed its run, please post the log created in your next reply.
Once the tool has completed its run, please post the log created in your next reply.
mrmarky
C:\Documents and Settings\mark.phelps\Desktop\HAMeb_check.exe
Fri 04/01/2011 at 15:55:35.13
Account active No
Local Group Memberships
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking for HelpAssistant directories ~~
none found
~~ Checking mbr ~~
~~ Checking for termsrv32.dll ~~
termsrv32.dll was not found
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv.dll
~~ Checking firewall ports ~~
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP"=3389:TCP:*:enabled:Remote Desktop "TCP"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"=3389:TCP:*:enabled:Remote Desktop "TCP"
~~ EOF ~~
Blottedisk
Hi mrmarky,
Your Remote Desktop ports are open. Do you use the Remote Desktop feature in your machine?
Your Remote Desktop ports are open. Do you use the Remote Desktop feature in your machine?
"3389:TCP"= 3389:TCP:Remote Desktop (TCP)
"3389:UDP"= 3389:UDP:Remote Desktop (UDP)
mrmarky
Hi mrmarky,
Your Remote Desktop ports are open. Do you use the Remote Desktop feature in your machine?
"3389:TCP"= 3389:TCP:Remote Desktop (TCP)
"3389:UDP"= 3389:UDP:Remote Desktop (UDP)
Would that mean I access my desktop from another machine? If so, no I do not use that.
mrmarky
Still there Blottedisk?
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI