Morik
Topic Starter
Computer was acting weird so I scanned with malware/super and now ran combofix. Here are results.
ComboFix 11-04-07.01 - CAPWN 04/07/2011 22:02:29.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.732 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Desktop\499wggr7.exe
c:\documents and settings\Administrator\Desktop\ComboFix.exe
c:\documents and settings\jhamilton\Desktop\ComboFix(1).exe
c:\documents and settings\kgreen.PCS\Desktop\clj4600pcl6winvista2kxp2003.exe
c:\documents and settings\kgreen\WINDOWS
c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
c:\program files\Analog Devices\Core\smax4pnp.exe
c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
c:\program files\Common Files\Microsoft Shared\Web Folders\MSONSEXT.DLL
c:\program files\Common Files\System\SNAPVIEW.OCX
c:\program files\Dell AIO Printer A920\dlbkbmgr.exe
c:\program files\HP\HP Software Update\HPWuSchd2.exe
c:\program files\Internet Explorer\custsat.dll
c:\program files\Internet Explorer\ieproxy.dll
c:\program files\Internet Explorer\Plugins\nppdf32.dll
c:\program files\Messenger\custsat.dll
c:\program files\Windows Media Player\dlimport.exe
c:\program files\Windows Media Player\LegitLibM.dll
c:\program files\Windows Media Player\wmdbexport.exe
c:\program files\Windows Media Player\wmlaunch.exe
c:\program files\Windows Media Player\wmpenc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnssci.dll
c:\program files\Windows Media Player\wmpshare.exe
c:\program files\Windows Media Player\wmpvis.dll
c:\program files\Windows Media Player\wmsetsdk.exe
c:\program files\Windows NT\Accessories\mswrd6.wpc
c:\program files\Windows NT\Accessories\mswrd8.wpc
c:\program files\Windows NT\Accessories\write.wpc
c:\program files\Windows NT\hypertrm.exe
c:\windows\apppatch\acadproc.dll
c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
c:\windows\ODEUNST.EXE
c:\windows\Setup1.exe
c:\windows\System\crlds3d.dll
c:\windows\system32\acelpdec.ax
c:\windows\system32\advpack.dll.mui
c:\windows\system32\audiodev.dll
c:\windows\system32\chcp.com
c:\windows\system32\comsdupd.exe
c:\windows\system32\dfshim.dll
c:\windows\system32\DIMM.DLL
c:\windows\system32\diskcomp.com
c:\windows\system32\diskcopy.com
c:\windows\system32\dlbkcinf.dll
c:\windows\system32\dlbkcoin.dll
c:\windows\system32\dlbkcomm.dll
c:\windows\system32\dlbkpwr.dll
c:\windows\system32\drivers\ADIHdAud.sys
c:\windows\system32\Drivers\hdaudbus.sys
c:\windows\system32\Drivers\Hdaudio.sys
c:\windows\system32\DRIVERS\igxpmp32.sys
c:\windows\system32\Drivers\mbamswissarmy.sys
c:\windows\system32\DRIVERS\secdrv.sys
c:\windows\system32\drivers\Senfilt.sys
c:\windows\system32\Drivers\sffp_mmc.sys
c:\windows\system32\Drivers\wpdusb.sys
c:\windows\system32\DRIVERS\WudfPf.sys
c:\windows\system32\DRIVERS\wudfrd.sys
c:\windows\system32\drmupgds.exe
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\faxpatch.exe
c:\windows\system32\format.com
c:\windows\system32\graftabl.com
c:\windows\system32\Hdaudprop.dll
c:\windows\system32\Hdaudpropres.dll
c:\windows\system32\Hdaudpropshortcut.exe
c:\windows\system32\hptcpmib.dll
c:\windows\system32\HpTcpMon.dll
c:\windows\system32\HPTcpMUI.dll
c:\windows\system32\hpzipm12.dll
c:\windows\system32\html.iec
c:\windows\system32\icardagt.exe
c:\windows\system32\icardres.dll
c:\windows\system32\icardres.dll.mui
c:\windows\system32\ieframe.dll.mui
c:\windows\system32\igldev32.dll
c:\windows\system32\iglicd32.dll
c:\windows\system32\igxpdv32.dll
c:\windows\system32\igxpdx32.dll
c:\windows\system32\igxpgd32.dll
c:\windows\system32\igxprd32.dll
c:\windows\system32\igxpun.exe
c:\windows\system32\imaadp32.acm
c:\windows\system32\infocardapi.dll
c:\windows\system32\infocardcpl.cpl
c:\windows\system32\INKED.DLL
c:\windows\system32\ivfsrc.ax
c:\windows\system32\LEX2KUSB.DLL
c:\windows\system32\LEXBCE.DLL
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\lexlmpm.dll
c:\windows\system32\LEXP2P32.DLL
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\MFPLAT.dll
c:\windows\system32\migpwd.exe
c:\windows\system32\milcore.dll
c:\windows\system32\mindex.dll
c:\windows\system32\mode.com
c:\windows\system32\more.com
c:\windows\system32\MP43DECD.dll
c:\windows\system32\mp4sdecd.dll
c:\windows\system32\MPG4DECD.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msadp32.acm
c:\windows\system32\msaud32.acm
c:\windows\system32\mscoree.dll
c:\windows\system32\msdelta.dll
c:\windows\system32\msg711.acm
c:\windows\system32\msg723.acm
c:\windows\system32\msgsm32.acm
c:\windows\system32\msh261.drv
c:\windows\system32\msh263.drv
c:\windows\system32\MSRDO20.DLL
c:\windows\system32\MSRTEDIT.DLL
c:\windows\system32\MSSTDFMT.DLL
c:\windows\system32\mucltui.dll
c:\windows\system32\mucltui.dll.mui
c:\windows\system32\muweb.dll
c:\windows\system32\netfxperf.dll
c:\windows\system32\ODESTKIT.DLL
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\PortableDeviceClassExtension.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceWiaCompat.dll
c:\windows\system32\PortableDeviceWMDRM.dll
c:\windows\system32\prntvpt.dll
c:\windows\system32\RDOCURS.DLL
c:\windows\system32\rgb9rast_2.dll
c:\windows\system32\SCP32.DLL
c:\windows\system32\spdwnwxp.exe
c:\windows\system32\spmsg2.dll
c:\windows\System32\spool\PRTPROCS\W32X86\DLBKPP5C.dll
c:\windows\System32\spool\PRTPROCS\W32X86\filterpipelineprintproc.dll
c:\windows\System32\spool\PRTPROCS\W32X86\hpzpp053.dll
c:\windows\System32\spool\PRTPROCS\W32X86\hpzpp5in.DLL
c:\windows\System32\spool\PRTPROCS\W32X86\mdippr.dll
c:\windows\system32\spupdsvc.exe
c:\windows\system32\spupdwxp.exe
c:\windows\system32\system
c:\windows\system32\taskman.exe
c:\windows\system32\temp.000
c:\windows\system32\tree.com
c:\windows\system32\tscupgrd.exe
c:\windows\system32\tssoft32.acm
c:\windows\system32\TsWpfWrp.exe
c:\windows\system32\UIAutomationCore.dll
c:\windows\system32\uwdf.exe
c:\windows\system32\VBAEN32.OLB
c:\windows\system32\VBAEND32.OLB
c:\windows\system32\VBAME.DLL
c:\windows\system32\VEN2232.OLB
c:\windows\system32\verclsid.exe
c:\windows\system32\wdfapi.dll
c:\windows\system32\wdfmgr.exe
c:\windows\system32\win.com
c:\windows\system32\WINSSPI.DLL
c:\windows\system32\WISPTIS.EXE
c:\windows\system32\wmdrmdev.dll
c:\windows\system32\wmdrmnet.dll
c:\windows\system32\wmidx.ocx
c:\windows\system32\wmpeffects.dll
c:\windows\system32\wmpencen.dll
c:\windows\system32\wmpmde.dll
c:\windows\system32\wmpps.dll
c:\windows\system32\wmpsrcwp.dll
c:\windows\system32\wmpstub.exe
c:\windows\system32\WMVADVD.dll
c:\windows\system32\WMVADVE.DLL
c:\windows\system32\wmvcore2.dll
c:\windows\system32\WMVDECOD.dll
c:\windows\system32\wmvdmoe.dll
c:\windows\system32\WMVENCOD.dll
c:\windows\system32\WMVSDECD.dll
c:\windows\system32\WMVSENCD.dll
c:\windows\system32\WMVXENCD.dll
c:\windows\system32\wpd_ci.dll
c:\windows\system32\wpdconns.dll
c:\windows\system32\wpdmtp.dll
c:\windows\system32\wpdmtpus.dll
c:\windows\system32\WpdShext.dll
c:\windows\system32\wpdshextautoplay.exe
c:\windows\system32\wpdshextres.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\wpdsp.dll
c:\windows\system32\wuapi.dll.mui
c:\windows\system32\wuaucpl.cpl.mui
c:\windows\system32\wuaueng.dll.mui
c:\windows\system32\wucltui.dll.mui
c:\windows\system32\WUDFCoinstaller.dll
c:\windows\system32\WudfHost.exe
c:\windows\system32\WudfPlatform.dll
c:\windows\System32\WUDFSvc.dll
c:\windows\system32\WUDFx.dll
c:\windows\system32\xpsp4res.dll
c:\windows\system32\xpsshhdr.dll
c:\windows\system32\xpssvcs.dll
.
.
\\.\PhysicalDrive0 - Bootkit TDL4 was found and disinfected
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_ADIHdAudAddService
——-\Service_SenFiltService
.
.
((((((((((((((((((((((((( Files Created from 2011-03-08 to 2011-04-08 )))))))))))))))))))))))))))))))
.
.
2011-04-07 21:18 . 2011-04-07 21:18 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-04-07 21:18 . 2011-04-07 21:18 ——– d—–w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2011-04-07 21:18 . 2011-04-07 21:18 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-03-28 14:30 . 2008-04-14 11:42 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2011-03-15 12:56 . 2011-03-15 12:56 ——– d–h–w- c:\documents and settings\All Users\Application Data\Common Files
2011-03-14 18:38 . 2011-03-14 18:38 ——– d—–w- c:\documents and settings\All Users\Application Data\hOnDaNm06321
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2003-03-31 12:00 439296 —-a-w- c:\windows\system32\shimgvw.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-06 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-06 162328]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-06 137752]
"ToolBoxFX"="c:\program files\HP\ToolBoxFX\bin\HPTLBXFX.exe" [2005-11-21 45056]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [2007-10-30 13801]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\sambar50\\bin\\server.exe"=
"c:\\Inetpub\\wwwroot\\RedeSetGrow\\RSGLauncher.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 12:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67656]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [3/25/2010 11:25 AM 30969208]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 10:37 PM 4640000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-SoundMAXPnP - c:\program files\Analog Devices\Core\smax4pnp.exe
HKLM-Run-Dell AIO Printer A920 - c:\program files\Dell AIO Printer A920\dlbkbmgr.exe
HKLM-Run-HP Software Update - c:\program files\HP\HP Software Update\HPWuSchd2.exe
HKLM-Run-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
Notify-avgrsstarter - avgrsstx.dll
Notify-NavLogon - (no file)
AddRemove-HDMI - c:\windows\system32\igxpun.exe
AddRemove-Windows Media Format Runtime - c:\program files\Windows Media Player\wmsetsdk.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-07 22:23
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(656)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(1844)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
.
**************************************************************************
.
Completion time: 2011-04-07 22:26:12 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-08 04:26
.
Pre-Run: 64,619,741,184 bytes free
Post-Run: 67,509,272,576 bytes free
.
- - End Of File - - 0CC51A4289CD04B5331BCBF4D903917B
ComboFix 11-04-07.01 - CAPWN 04/07/2011 22:02:29.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.732 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Desktop\499wggr7.exe
c:\documents and settings\Administrator\Desktop\ComboFix.exe
c:\documents and settings\jhamilton\Desktop\ComboFix(1).exe
c:\documents and settings\kgreen.PCS\Desktop\clj4600pcl6winvista2kxp2003.exe
c:\documents and settings\kgreen\WINDOWS
c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
c:\program files\Analog Devices\Core\smax4pnp.exe
c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
c:\program files\Common Files\Microsoft Shared\Web Folders\MSONSEXT.DLL
c:\program files\Common Files\System\SNAPVIEW.OCX
c:\program files\Dell AIO Printer A920\dlbkbmgr.exe
c:\program files\HP\HP Software Update\HPWuSchd2.exe
c:\program files\Internet Explorer\custsat.dll
c:\program files\Internet Explorer\ieproxy.dll
c:\program files\Internet Explorer\Plugins\nppdf32.dll
c:\program files\Messenger\custsat.dll
c:\program files\Windows Media Player\dlimport.exe
c:\program files\Windows Media Player\LegitLibM.dll
c:\program files\Windows Media Player\wmdbexport.exe
c:\program files\Windows Media Player\wmlaunch.exe
c:\program files\Windows Media Player\wmpenc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnssci.dll
c:\program files\Windows Media Player\wmpshare.exe
c:\program files\Windows Media Player\wmpvis.dll
c:\program files\Windows Media Player\wmsetsdk.exe
c:\program files\Windows NT\Accessories\mswrd6.wpc
c:\program files\Windows NT\Accessories\mswrd8.wpc
c:\program files\Windows NT\Accessories\write.wpc
c:\program files\Windows NT\hypertrm.exe
c:\windows\apppatch\acadproc.dll
c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
c:\windows\ODEUNST.EXE
c:\windows\Setup1.exe
c:\windows\System\crlds3d.dll
c:\windows\system32\acelpdec.ax
c:\windows\system32\advpack.dll.mui
c:\windows\system32\audiodev.dll
c:\windows\system32\chcp.com
c:\windows\system32\comsdupd.exe
c:\windows\system32\dfshim.dll
c:\windows\system32\DIMM.DLL
c:\windows\system32\diskcomp.com
c:\windows\system32\diskcopy.com
c:\windows\system32\dlbkcinf.dll
c:\windows\system32\dlbkcoin.dll
c:\windows\system32\dlbkcomm.dll
c:\windows\system32\dlbkpwr.dll
c:\windows\system32\drivers\ADIHdAud.sys
c:\windows\system32\Drivers\hdaudbus.sys
c:\windows\system32\Drivers\Hdaudio.sys
c:\windows\system32\DRIVERS\igxpmp32.sys
c:\windows\system32\Drivers\mbamswissarmy.sys
c:\windows\system32\DRIVERS\secdrv.sys
c:\windows\system32\drivers\Senfilt.sys
c:\windows\system32\Drivers\sffp_mmc.sys
c:\windows\system32\Drivers\wpdusb.sys
c:\windows\system32\DRIVERS\WudfPf.sys
c:\windows\system32\DRIVERS\wudfrd.sys
c:\windows\system32\drmupgds.exe
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\faxpatch.exe
c:\windows\system32\format.com
c:\windows\system32\graftabl.com
c:\windows\system32\Hdaudprop.dll
c:\windows\system32\Hdaudpropres.dll
c:\windows\system32\Hdaudpropshortcut.exe
c:\windows\system32\hptcpmib.dll
c:\windows\system32\HpTcpMon.dll
c:\windows\system32\HPTcpMUI.dll
c:\windows\system32\hpzipm12.dll
c:\windows\system32\html.iec
c:\windows\system32\icardagt.exe
c:\windows\system32\icardres.dll
c:\windows\system32\icardres.dll.mui
c:\windows\system32\ieframe.dll.mui
c:\windows\system32\igldev32.dll
c:\windows\system32\iglicd32.dll
c:\windows\system32\igxpdv32.dll
c:\windows\system32\igxpdx32.dll
c:\windows\system32\igxpgd32.dll
c:\windows\system32\igxprd32.dll
c:\windows\system32\igxpun.exe
c:\windows\system32\imaadp32.acm
c:\windows\system32\infocardapi.dll
c:\windows\system32\infocardcpl.cpl
c:\windows\system32\INKED.DLL
c:\windows\system32\ivfsrc.ax
c:\windows\system32\LEX2KUSB.DLL
c:\windows\system32\LEXBCE.DLL
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\lexlmpm.dll
c:\windows\system32\LEXP2P32.DLL
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\MFPLAT.dll
c:\windows\system32\migpwd.exe
c:\windows\system32\milcore.dll
c:\windows\system32\mindex.dll
c:\windows\system32\mode.com
c:\windows\system32\more.com
c:\windows\system32\MP43DECD.dll
c:\windows\system32\mp4sdecd.dll
c:\windows\system32\MPG4DECD.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msadp32.acm
c:\windows\system32\msaud32.acm
c:\windows\system32\mscoree.dll
c:\windows\system32\msdelta.dll
c:\windows\system32\msg711.acm
c:\windows\system32\msg723.acm
c:\windows\system32\msgsm32.acm
c:\windows\system32\msh261.drv
c:\windows\system32\msh263.drv
c:\windows\system32\MSRDO20.DLL
c:\windows\system32\MSRTEDIT.DLL
c:\windows\system32\MSSTDFMT.DLL
c:\windows\system32\mucltui.dll
c:\windows\system32\mucltui.dll.mui
c:\windows\system32\muweb.dll
c:\windows\system32\netfxperf.dll
c:\windows\system32\ODESTKIT.DLL
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\PortableDeviceClassExtension.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceWiaCompat.dll
c:\windows\system32\PortableDeviceWMDRM.dll
c:\windows\system32\prntvpt.dll
c:\windows\system32\RDOCURS.DLL
c:\windows\system32\rgb9rast_2.dll
c:\windows\system32\SCP32.DLL
c:\windows\system32\spdwnwxp.exe
c:\windows\system32\spmsg2.dll
c:\windows\System32\spool\PRTPROCS\W32X86\DLBKPP5C.dll
c:\windows\System32\spool\PRTPROCS\W32X86\filterpipelineprintproc.dll
c:\windows\System32\spool\PRTPROCS\W32X86\hpzpp053.dll
c:\windows\System32\spool\PRTPROCS\W32X86\hpzpp5in.DLL
c:\windows\System32\spool\PRTPROCS\W32X86\mdippr.dll
c:\windows\system32\spupdsvc.exe
c:\windows\system32\spupdwxp.exe
c:\windows\system32\system
c:\windows\system32\taskman.exe
c:\windows\system32\temp.000
c:\windows\system32\tree.com
c:\windows\system32\tscupgrd.exe
c:\windows\system32\tssoft32.acm
c:\windows\system32\TsWpfWrp.exe
c:\windows\system32\UIAutomationCore.dll
c:\windows\system32\uwdf.exe
c:\windows\system32\VBAEN32.OLB
c:\windows\system32\VBAEND32.OLB
c:\windows\system32\VBAME.DLL
c:\windows\system32\VEN2232.OLB
c:\windows\system32\verclsid.exe
c:\windows\system32\wdfapi.dll
c:\windows\system32\wdfmgr.exe
c:\windows\system32\win.com
c:\windows\system32\WINSSPI.DLL
c:\windows\system32\WISPTIS.EXE
c:\windows\system32\wmdrmdev.dll
c:\windows\system32\wmdrmnet.dll
c:\windows\system32\wmidx.ocx
c:\windows\system32\wmpeffects.dll
c:\windows\system32\wmpencen.dll
c:\windows\system32\wmpmde.dll
c:\windows\system32\wmpps.dll
c:\windows\system32\wmpsrcwp.dll
c:\windows\system32\wmpstub.exe
c:\windows\system32\WMVADVD.dll
c:\windows\system32\WMVADVE.DLL
c:\windows\system32\wmvcore2.dll
c:\windows\system32\WMVDECOD.dll
c:\windows\system32\wmvdmoe.dll
c:\windows\system32\WMVENCOD.dll
c:\windows\system32\WMVSDECD.dll
c:\windows\system32\WMVSENCD.dll
c:\windows\system32\WMVXENCD.dll
c:\windows\system32\wpd_ci.dll
c:\windows\system32\wpdconns.dll
c:\windows\system32\wpdmtp.dll
c:\windows\system32\wpdmtpus.dll
c:\windows\system32\WpdShext.dll
c:\windows\system32\wpdshextautoplay.exe
c:\windows\system32\wpdshextres.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\wpdsp.dll
c:\windows\system32\wuapi.dll.mui
c:\windows\system32\wuaucpl.cpl.mui
c:\windows\system32\wuaueng.dll.mui
c:\windows\system32\wucltui.dll.mui
c:\windows\system32\WUDFCoinstaller.dll
c:\windows\system32\WudfHost.exe
c:\windows\system32\WudfPlatform.dll
c:\windows\System32\WUDFSvc.dll
c:\windows\system32\WUDFx.dll
c:\windows\system32\xpsp4res.dll
c:\windows\system32\xpsshhdr.dll
c:\windows\system32\xpssvcs.dll
.
.
\\.\PhysicalDrive0 - Bootkit TDL4 was found and disinfected
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_ADIHdAudAddService
——-\Service_SenFiltService
.
.
((((((((((((((((((((((((( Files Created from 2011-03-08 to 2011-04-08 )))))))))))))))))))))))))))))))
.
.
2011-04-07 21:18 . 2011-04-07 21:18 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-04-07 21:18 . 2011-04-07 21:18 ——– d—–w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2011-04-07 21:18 . 2011-04-07 21:18 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-03-28 14:30 . 2008-04-14 11:42 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2011-03-15 12:56 . 2011-03-15 12:56 ——– d–h–w- c:\documents and settings\All Users\Application Data\Common Files
2011-03-14 18:38 . 2011-03-14 18:38 ——– d—–w- c:\documents and settings\All Users\Application Data\hOnDaNm06321
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2003-03-31 12:00 439296 —-a-w- c:\windows\system32\shimgvw.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-06 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-06 162328]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-06 137752]
"ToolBoxFX"="c:\program files\HP\ToolBoxFX\bin\HPTLBXFX.exe" [2005-11-21 45056]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [2007-10-30 13801]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\sambar50\\bin\\server.exe"=
"c:\\Inetpub\\wwwroot\\RedeSetGrow\\RSGLauncher.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 12:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67656]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [3/25/2010 11:25 AM 30969208]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 10:37 PM 4640000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-SoundMAXPnP - c:\program files\Analog Devices\Core\smax4pnp.exe
HKLM-Run-Dell AIO Printer A920 - c:\program files\Dell AIO Printer A920\dlbkbmgr.exe
HKLM-Run-HP Software Update - c:\program files\HP\HP Software Update\HPWuSchd2.exe
HKLM-Run-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
Notify-avgrsstarter - avgrsstx.dll
Notify-NavLogon - (no file)
AddRemove-HDMI - c:\windows\system32\igxpun.exe
AddRemove-Windows Media Format Runtime - c:\program files\Windows Media Player\wmsetsdk.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-07 22:23
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(656)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(1844)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
.
**************************************************************************
.
Completion time: 2011-04-07 22:26:12 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-08 04:26
.
Pre-Run: 64,619,741,184 bytes free
Post-Run: 67,509,272,576 bytes free
.
- - End Of File - - 0CC51A4289CD04B5331BCBF4D903917B