Deleted Member
Topic Starter
I got a laptop that I'd like to pass to my parents. I figured out that no antivirus was installed (o_O), and installed ESET Smart Security, but its services are prevented from starting. After some workaround I was able to run it, and it reported that memory is infected with Win32/Sirefef.DA, but ESET cannot clear it.
Could you please help me to get rid of it?
Thank you very much!
DDS log:
—————
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 17:51:11.25 on Sun 07/29/2012
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_05
Microsoft Windows XP Professional 5.1.2600.3.1251.7.1033.18.1022.609 [GMT -7:00]
.
AV: ESET Smart Security 5.2 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\184393290:3043033845.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Wave Systems Corp\Common\DataServer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\SciTegic\apps\scitegic\core\packages_win32\apache\httpd-2.0.55\bin\apache.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.7\bin\tcsd_win32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Ally\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
C:\Program Files\Apoint\HidFind.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Apoint\Apntex.exe
C:\Documents and Settings\Ally\Desktop\dds.scr
C:\Program Files\SciTegic\apps\scitegic\core\packages_win32\apache\httpd-2.0.55\bin\apache.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyServer = proxy-server.hpw.pri.bms.com:8080
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: 1 (0x1): {02478d38-c3f9-4efb-9b51-7695eca05670} - Yahoo! Toolbar Helper
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\RegistryBooster.exe /S
uRun: [Google Update] "c:\documents and settings\ally\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [NvCplDaemon] "RUNDLL32.EXE" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] "nwiz.exe" /installquiet
mRun: [NVHotkey] "rundll32.exe" nvHotkey.dll,Start
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe"
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [HP Software Update] "c:\program files\hewlett-packard\hp software update\HPWuSchd.exe"
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [Document Manager] c:\program files\wave systems corp\services manager\docmgr\bin\docmgr.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\embass~1.lnk - c:\program files\wave systems corp\services manager\secure update\AutoUpdate.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: mswsock.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {8F0DF9DB-AA5A-4ED0-9176-1C4A9C762C59} - hxxp://stus3.bms.com/sametime/stmeetingroomclient/STJNILoader.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://genego.webex.com/client/v_mywebex-t20/webex/ieatgpc.cab
TCP: {DE102038-EEE8-471F-8B13-372648ECA3EF} = 66.78.210.254,66.78.202.254
AppInit_DLLs: wxvault.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 wvauth
LSA: Notification Packages = scecli scecli
.
============= SERVICES / DRIVERS ===============
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2012-3-14 120152]
R2 MSSQL$ACT7;SQL Server (ACT7);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2006-6-28 28952920]
R2 scitegic_apache_1;scitegic_apache_6_1_5;c:\program files\scitegic\apps\scitegic\core\packages_win32\apache\httpd-2.0.55\bin\Apache.exe [2006-2-15 13824]
S2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2012-3-7 913144]
S2 SPService;SPService;c:\windows\system32\svchost.exe -k netsvc [2004-8-11 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-30 257696]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [2005-8-3 4736]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys –> c:\windows\system32\drivers\motodrv.sys [?]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [2005-8-3 8960]
S3 PortAcc;Spearit Port Access;c:\program files\laplink\pcmover\PortAcc.sys [2007-11-1 16176]
S3 SirefefRemover;SirefefRemover;\??\c:\docume~1\ally\locals~1\temp\559c268d.tmp –> c:\docume~1\ally\locals~1\temp\559c268d.tmp [?]
.
=============== Created Last 30 ================
.
2012-07-01 03:16:16 ——– d—–w- c:\docume~1\ally\applic~1\FixZeroAccess
.
==================== Find3M ====================
.
2012-06-06 03:50:30 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-06 03:50:30 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-31 13:22:09 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08:26 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-15 13:20:33 1863168 —-a-w- c:\windows\system32\win32k.sys
2012-05-11 14:42:33 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42:33 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38:02 385024 —-a-w- c:\windows\system32\html.iec
2012-05-04 13:16:13 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32:19 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2008-05-31 01:39:22 14613912 -c–a-w- c:\program files\Install_ICQ6.exe
2008-03-05 23:34:32 28668101 -c–a-w- c:\program files\R-2.3.1-win32.exe
2007-12-30 00:56:02 8759168 -c–a-w- c:\program files\winamp551_full_emusic-7plus_en-us.exe
2007-12-04 00:57:55 6820528 -c–a-w- c:\program files\FirefoxGoogleToolbarSetup.exe
2007-11-16 22:56:49 2155208 -c–a-w- c:\program files\total_commander702a.exe
2007-10-26 18:34:36 23876904 -c–a-w- c:\program files\SkypeSetup.exe
2007-08-29 00:25:31 1421234 -c–a-w- c:\program files\VNCNavigatorFree.exe
2007-08-27 22:24:36 471216 -c–a-w- c:\program files\msgr8us.exe
2007-08-27 21:44:40 50009400 -c–a-w- c:\program files\iTunesSetup.exe
2007-05-22 17:52:02 11552256 -c–a-w- c:\program files\AudioConverter5-4.exe
2007-05-04 22:03:26 3225088 -c–a-w- c:\program files\1ClickNew.msi
2006-11-29 00:10:23 18695520 -c–a-w- c:\program files\cdpn901.exe
2006-11-28 21:58:32 2387480 -c–a-w- c:\program files\SVGView.exe
2006-10-26 22:31:44 1645320 -c–a-w- c:\program files\gdiplus.dll
2006-10-26 22:31:14 1779200 -c–a-w- c:\program files\dchip2006.exe
2006-09-26 20:34:56 16230664 -c–a-w- c:\program files\j2re-1_4_2_12-windows-i586-p.exe
2006-09-18 18:34:31 1531784 -c–a-w- c:\program files\googletalk-setup.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST9100824AS rev.8.03 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8719ACA0]<<
_asm { MOV EAX, [ESP+0x4]; MOV ECX, [EAX+0x28]; PUSH EBP; MOV EBP, [ECX+0x4]; PUSH ESI; MOV ESI, [ESP+0x10]; PUSH EDI; MOV EDI, [ESI+0x60]; MOV AL, [EDI]; CMP AL, 0x16; JNZ 0x36; PUSH ESI; }
1 ntkrnlpa!IofCallDriver[0x804EF1B0] -> \Device\Harddisk0\DR0[0x8737CAB8]
3 CLASSPNP[0xF7592FD7] -> ntkrnlpa!IofCallDriver[0x804EF1B0] -> [0x8716D1F0]
\Driver\00000675[0x87245A18] -> IRP_MJ_CREATE -> 0x8719ACA0
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8731D31B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 17:53:32.29 ===============
Could you please help me to get rid of it?
Thank you very much!
DDS log:
—————
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 17:51:11.25 on Sun 07/29/2012
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_05
Microsoft Windows XP Professional 5.1.2600.3.1251.7.1033.18.1022.609 [GMT -7:00]
.
AV: ESET Smart Security 5.2 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\184393290:3043033845.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Wave Systems Corp\Common\DataServer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\SciTegic\apps\scitegic\core\packages_win32\apache\httpd-2.0.55\bin\apache.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.7\bin\tcsd_win32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Ally\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
C:\Program Files\Apoint\HidFind.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Apoint\Apntex.exe
C:\Documents and Settings\Ally\Desktop\dds.scr
C:\Program Files\SciTegic\apps\scitegic\core\packages_win32\apache\httpd-2.0.55\bin\apache.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyServer = proxy-server.hpw.pri.bms.com:8080
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: 1 (0x1): {02478d38-c3f9-4efb-9b51-7695eca05670} - Yahoo! Toolbar Helper
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\RegistryBooster.exe /S
uRun: [Google Update] "c:\documents and settings\ally\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [NvCplDaemon] "RUNDLL32.EXE" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] "nwiz.exe" /installquiet
mRun: [NVHotkey] "rundll32.exe" nvHotkey.dll,Start
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe"
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [HP Software Update] "c:\program files\hewlett-packard\hp software update\HPWuSchd.exe"
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [Document Manager] c:\program files\wave systems corp\services manager\docmgr\bin\docmgr.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\embass~1.lnk - c:\program files\wave systems corp\services manager\secure update\AutoUpdate.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: mswsock.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {8F0DF9DB-AA5A-4ED0-9176-1C4A9C762C59} - hxxp://stus3.bms.com/sametime/stmeetingroomclient/STJNILoader.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://genego.webex.com/client/v_mywebex-t20/webex/ieatgpc.cab
TCP: {DE102038-EEE8-471F-8B13-372648ECA3EF} = 66.78.210.254,66.78.202.254
AppInit_DLLs: wxvault.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 wvauth
LSA: Notification Packages = scecli scecli
.
============= SERVICES / DRIVERS ===============
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2012-3-14 120152]
R2 MSSQL$ACT7;SQL Server (ACT7);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2006-6-28 28952920]
R2 scitegic_apache_1;scitegic_apache_6_1_5;c:\program files\scitegic\apps\scitegic\core\packages_win32\apache\httpd-2.0.55\bin\Apache.exe [2006-2-15 13824]
S2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2012-3-7 913144]
S2 SPService;SPService;c:\windows\system32\svchost.exe -k netsvc [2004-8-11 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-30 257696]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [2005-8-3 4736]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys –> c:\windows\system32\drivers\motodrv.sys [?]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [2005-8-3 8960]
S3 PortAcc;Spearit Port Access;c:\program files\laplink\pcmover\PortAcc.sys [2007-11-1 16176]
S3 SirefefRemover;SirefefRemover;\??\c:\docume~1\ally\locals~1\temp\559c268d.tmp –> c:\docume~1\ally\locals~1\temp\559c268d.tmp [?]
.
=============== Created Last 30 ================
.
2012-07-01 03:16:16 ——– d—–w- c:\docume~1\ally\applic~1\FixZeroAccess
.
==================== Find3M ====================
.
2012-06-06 03:50:30 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-06 03:50:30 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-31 13:22:09 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08:26 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-15 13:20:33 1863168 —-a-w- c:\windows\system32\win32k.sys
2012-05-11 14:42:33 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42:33 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38:02 385024 —-a-w- c:\windows\system32\html.iec
2012-05-04 13:16:13 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32:19 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2008-05-31 01:39:22 14613912 -c–a-w- c:\program files\Install_ICQ6.exe
2008-03-05 23:34:32 28668101 -c–a-w- c:\program files\R-2.3.1-win32.exe
2007-12-30 00:56:02 8759168 -c–a-w- c:\program files\winamp551_full_emusic-7plus_en-us.exe
2007-12-04 00:57:55 6820528 -c–a-w- c:\program files\FirefoxGoogleToolbarSetup.exe
2007-11-16 22:56:49 2155208 -c–a-w- c:\program files\total_commander702a.exe
2007-10-26 18:34:36 23876904 -c–a-w- c:\program files\SkypeSetup.exe
2007-08-29 00:25:31 1421234 -c–a-w- c:\program files\VNCNavigatorFree.exe
2007-08-27 22:24:36 471216 -c–a-w- c:\program files\msgr8us.exe
2007-08-27 21:44:40 50009400 -c–a-w- c:\program files\iTunesSetup.exe
2007-05-22 17:52:02 11552256 -c–a-w- c:\program files\AudioConverter5-4.exe
2007-05-04 22:03:26 3225088 -c–a-w- c:\program files\1ClickNew.msi
2006-11-29 00:10:23 18695520 -c–a-w- c:\program files\cdpn901.exe
2006-11-28 21:58:32 2387480 -c–a-w- c:\program files\SVGView.exe
2006-10-26 22:31:44 1645320 -c–a-w- c:\program files\gdiplus.dll
2006-10-26 22:31:14 1779200 -c–a-w- c:\program files\dchip2006.exe
2006-09-26 20:34:56 16230664 -c–a-w- c:\program files\j2re-1_4_2_12-windows-i586-p.exe
2006-09-18 18:34:31 1531784 -c–a-w- c:\program files\googletalk-setup.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST9100824AS rev.8.03 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8719ACA0]<<
_asm { MOV EAX, [ESP+0x4]; MOV ECX, [EAX+0x28]; PUSH EBP; MOV EBP, [ECX+0x4]; PUSH ESI; MOV ESI, [ESP+0x10]; PUSH EDI; MOV EDI, [ESI+0x60]; MOV AL, [EDI]; CMP AL, 0x16; JNZ 0x36; PUSH ESI; }
1 ntkrnlpa!IofCallDriver[0x804EF1B0] -> \Device\Harddisk0\DR0[0x8737CAB8]
3 CLASSPNP[0xF7592FD7] -> ntkrnlpa!IofCallDriver[0x804EF1B0] -> [0x8716D1F0]
\Driver\00000675[0x87245A18] -> IRP_MJ_CREATE -> 0x8719ACA0
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8731D31B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 17:53:32.29 ===============