Ran this ComboFix:
===========================
ComboFix 08-06-11.3 - Administrator 2008-06-13 19:01:20.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1521 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScripts.txt
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-05-13 to 2008-06-13 )))))))))))))))))))))))))))))))
.
2008-06-13 14:20 . 2008-06-13 14:20 d——– C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-06-13 10:12 . 2008-06-13 10:12 d——– C:\Program Files\Windows Sidebar
2008-06-13 10:11 . 2008-06-13 10:37 d——– C:\Program Files\Norton 360
2008-06-13 10:09 . 2008-06-13 10:13 123,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-06-13 10:09 . 2008-06-13 10:13 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-06-13 10:09 . 2008-06-13 10:13 10,563 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-06-13 10:09 . 2008-06-13 10:13 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-06-13 10:08 . 2008-06-13 10:13 d——– C:\Program Files\Symantec
2008-06-13 09:25 . 2008-06-13 10:41 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2008-06-12 23:07 . 2008-06-13 09:24 d——– C:\WINDOWS\system32\CatRoot_bak
2008-06-12 22:52 . 2008-06-12 22:52 14,419 –a—— C:\WINDOWS\DrvmCDB_log
2008-06-12 22:32 . 2008-06-12 22:32 d——– C:\Documents and Settings\Administrator\Application Data\Motive
2008-06-12 22:12 . 2008-06-13 16:53 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-06-12 22:12 . 2008-06-12 22:12 1,409 –a—— C:\WINDOWS\QTFont.for
2008-06-12 22:11 . 2008-06-12 22:15 d——– C:\Documents and Settings\Administrator\Application Data\GTek
2008-06-12 18:57 . 2004-08-04 03:56 33,280 –a—— C:\WINDOWS\system32\rundll32.exe
2008-06-12 18:57 . 2004-08-04 03:56 33,280 –a—— C:\WINDOWS\system32\dllcache\rundll32.exe
2008-06-12 18:43 . 2008-06-12 18:43 d——– C:\Documents and Settings\All Users\Symantec Temporary Files
2008-06-12 15:04 . 2008-06-12 15:04 d——– C:\_OTMoveIt
2008-06-12 14:07 . 2008-06-12 14:07 d——– C:\Deckard
2008-06-12 12:31 . 2008-06-13 10:06 d——– C:\fixwareout
2008-06-12 00:15 . 2008-06-13 19:04 d——– C:\Program Files\Common Files\Symantec Shared
2008-06-12 00:15 . 2008-06-13 15:18 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-11 23:14 . 2001-08-18 07:00 31,744 –a—— C:\WINDOWS\system32\RUNDLL32.ol2
2008-06-11 18:34 . 2008-06-11 18:34 d——– C:\Program Files\smitRem
2008-06-11 17:24 . 2008-06-11 17:25 d——– C:\Documents and Settings\Sean\Temp
2008-06-11 17:09 . 2008-06-11 17:09 d——– C:\Documents and Settings\Administrator\Program Files
2008-06-11 17:07 . 2008-06-11 17:07 72,192 –a—— C:\WINDOWS\tasklist.exe
2008-06-11 15:27 . 2008-06-11 15:27 d——– C:\WINDOWS\system32\Dell
2008-06-11 14:55 . 2008-06-11 14:55 d——– C:\Documents and Settings\Sean\New Folder
2008-06-10 13:44 . 2008-06-10 13:44 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-06-10 13:44 . 2008-06-10 13:44 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-10 13:44 . 2008-06-10 13:44 d——– C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-06-10 13:44 . 2008-06-09 20:13 34,296 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-10 13:44 . 2008-06-09 20:13 15,864 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-06-09 18:12 . 2008-06-10 11:09 200,448 –a—— C:\WINDOWS\system32\drivers\ndisio.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-12 23:00 ——— d—–w C:\Documents and Settings\Sean\Application Data\Registry Booster
2008-06-11 19:27 ——— d—–w C:\Program Files\Dell
2008-06-10 19:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-10 18:49 ——— d—–w C:\Program Files\WildTangent
2008-06-10 18:47 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-04-30 20:34 ——— d—–w C:\Documents and Settings\Sean\Application Data\TmpRecentIcons
2008-04-29 23:40 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-04-16 01:51 ——— d—–w C:\Program Files\Java
2008-04-14 23:11 15,772 —-a-w C:\Documents and Settings\Sean\Application Data\wklnhst.dat
2006-12-22 03:46 88 –sh–r C:\WINDOWS\system32\F7AEBA1285.sys
2006-12-22 03:46 3,350 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
——- Sigcheck ——-
2008-04-13 20:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\svchost.exe
2008-04-14 21:23 17408 016e99a00bf65380352ad1ba8ee5f151 C:\WINDOWS\system32\svchost.exe
2006-04-20 08:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 12:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2004-08-10 05:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 07:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 15:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\tcpip.sys
2007-10-30 13:20 360064 ecf02439fd31bbd0dbc2ec05600cf08a C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 13:20 360064 ecf02439fd31bbd0dbc2ec05600cf08a C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 20:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\winlogon.exe
2004-08-10 05:00 506368 694c72f19fbb3c1e8a33f30381fe151e C:\WINDOWS\system32\winlogon.exe
2007-06-13 06:23 1035776 5eb4536b90e8ece755b5d5c90c56e173 C:\WINDOWS\explorer.exe
2007-06-13 07:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-10 05:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2008-04-13 20:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\explorer.exe
2008-04-13 20:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\services.exe
2004-08-10 05:00 110592 e6dcca66a861ad511eb4b36471621b99 C:\WINDOWS\system32\services.exe
2008-04-13 20:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lsass.exe
2004-08-10 05:00 14848 ce01c0db9fa81bf4bc082448eaf21124 C:\WINDOWS\system32\lsass.exe
.
((((((((((((((((((((((((((((( snapshot_2008-06-13_10.53.18.01 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-13 14:37:49 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 23:03:36 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 23:04:20 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_5fc.dat
+ 2008-06-13 23:03:53 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_788.dat
+ 2008-06-13 23:04:25 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_7d0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2008-02-23 22:08 349552 –a—— C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-06-13 10:12 116088 –a—— C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@={4433A54A-1AC8-432F-90FC-85F045CF383C}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@={F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@={476D0EA3-80F9-48B5-B70B-05E677C9C148}
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-02-26 04:34 576352 –a—— C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-02-26 04:34 576352 –a—— C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-02-26 04:34 576352 –a—— C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00 15360]
"DellTransferAgent"="C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe" [2007-11-13 17:46 135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 14:01 67584]
"SigmatelSysTrayApp"="stsystra.exe" [2006-02-10 18:17 282624 C:\WINDOWS\stsystra.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 21:05 344064]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 03:12 94208]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 10:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 10:44 81920]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 05:20 122940]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-19 15:39 1838592]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-09-08 19:20 110592]
"DLADiag"="C:\WINDOWS\DLADiag.EXE" [2005-08-25 12:16 57403]
"pdfSaver3"="" []
"602PC SUITE PDF Saver"="C:\Program Files\Common Files\soft602\pdfSaver.exe" [2005-08-31 16:00 49152]
"Verizon_McciTrayApp"="C:\Program Files\Verizon\McciTrayApp.exe" [2007-03-11 17:37 936960]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2001-10-12 08:42 36864]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"jtpjhttp"="" []
"hfjtnfbj"="C:\DOCUME~1\Sean\LOCALS~1\Temp\dhnffjppjt.nls WLEntryPoint" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-18 15:37 51048]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [2008-02-26 10:50 988512]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"InetChk"="C:\WINDOWS\TEMP\ms1209582824.exe" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-09-06 02:11:27 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist Express Customer]
C:\Program Files\Citrix\GoToAssist Express Customer\43\g2ax_winlogon.dll 2007-12-15 16:17 45368 C:\Program Files\Citrix\GoToAssist Express Customer\43\g2ax_winlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"21152:TCP"= 21152:TCP:@xpsp2res.dll,-22005
"14415:TCP"= 14415:TCP:@xpsp2res.dll,-22005
"60154:TCP"= 60154:TCP:@xpsp2res.dll,-22005
"29769:TCP"= 29769:TCP:@xpsp2res.dll,-22005
R1 DLADiagN;DLADiagN;C:\WINDOWS\system32\Drivers\DLADiagN.SYS [2005-08-25 12:16]
R1 DLAPMonN;DLAPMonN;C:\WINDOWS\system32\Drivers\DLAPMonN.SYS [2005-08-25 12:16]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
S2 NtmsSvc Service;Removable Storage NtmsSvc Service;C:\DOCUME~1\Sean\LOCALS~1\Temp\38.tmp []
S2 sqlagent$microsoftsmlbiznla;SQLAgent$MICROSOFTSMLBIZ SQLAgent$MICROSOFTSMLBIZNla;C:\DOCUME~1\Sean\LOCALS~1\Temp\22B6.tmp []
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
S3 GoToAssist Express Customer;GoToAssist Express Customer;"C:\Program Files\Citrix\GoToAssist Express Customer\43\g2ax_service.exe" Start=service []
S4 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" []
*Newly Created Service* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\KB910393]
"rundll32.exe advpack.dll,LaunchINFSection C:\\WINDOWS\\INF\\EasyCDBlock.inf,PerUserInstall"
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-13 19:10:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\NtmsSvc Service]
"ImagePath"="C:\DOCUME~1\Sean\LOCALS~1\Temp\38.tmp srv"
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\sqlagent$microsoftsmlbiznla]
"ImagePath"="C:\DOCUME~1\Sean\LOCALS~1\Temp\22B6.tmp srv"
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Citrix\GoToAssist Express Customer\43\g2ax_winlogon.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-06-13 19:14:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-13 23:13:55
ComboFix2.txt 2008-06-13 21:28:02
ComboFix3.txt 2008-06-13 16:18:03
ComboFix4.txt 2008-06-13 14:53:49
ComboFix5.txt 2008-06-13 02:17:57
Pre-Run: 49,993,052,160 bytes free
Post-Run: 49,985,667,072 bytes free
227 — E O F — 2008-04-13 07:03:01
======================================
Then downloaded and ran Express Scan on Dr. Web. Worried that the infected files were removed -
explorer.exe
lsass.exe
services.exe
svchost.exe
winlogon.exe
…and there was no CD available to replace them. I assume you will show me how to restore these files from the item we downloaded from Windows???
DrWeb.cvs contained:
===================================
explorer.exe;c:\windows;Trojan.Starter.384;Cured.;
lsass.exe;c:\windows\system32;Trojan.Starter.384;Cured.;
services.exe;c:\windows\system32;Trojan.Starter.384;Cured.;
svchost.exe;c:\windows\system32;Trojan.Starter.384;Cured.;
winlogon.exe;c:\windows\system32;Trojan.Starter.384;Cured.;
===================================
Dr. Web is doing a complete scan now.
Jim