Hello
We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Please include the C:\ComboFix.txt in your next reply for further review.
Thanks again for your help. The following is the ComboFix log
ComboFix 08-11-27.03 - Dave Schoenung 2008-11-27 18:24:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.666 [GMT -5:00]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\Temp
c:\windows\system32\drivers\TDSSmqct.sys
c:\windows\system32\TDSSbrsr.dll
c:\windows\system32\TDSSkkbu.log
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSoiqh.dll
c:\windows\system32\TDSSorvd.dat
c:\windows\system32\TDSSoxwp.dll
c:\windows\system32\TDSSrhyp.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsihc.dll
c:\windows\system32\TDSSxfuv.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_TDSSSERV.SYS
——-\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((( Files Created from 2008-10-27 to 2008-11-27 )))))))))))))))))))))))))))))))
.
2008-11-27 18:20 . 2008-11-27 18:20 d——– C:\CF
2008-11-27 10:32 . 2008-11-27 10:32 577,024 –a—— c:\windows\system32\dllcache\user32.dll
2008-11-27 10:30 . 2008-11-27 10:30 d——– c:\windows\ERUNT
2008-11-27 10:21 . 2008-11-27 10:40 d——– C:\SDFix
2008-11-26 23:08 . 2008-11-26 23:08 d——– c:\program files\Trend Micro
2008-11-26 18:56 . 2008-11-26 18:56 d–h—– C:\$AVG8.VAULT$
2008-11-26 18:30 . 2008-11-26 18:30 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2008-11-26 18:30 . 2008-11-26 18:30 10,520 –a—— c:\windows\system32\avgrsstx.dll
2008-11-26 18:29 . 2008-11-27 10:41 d——– c:\windows\system32\drivers\Avg
2008-11-26 18:29 . 2008-11-26 18:29 d——– c:\program files\AVG
2008-11-26 18:29 . 2008-11-26 22:32 d——– c:\documents and settings\Dave Schoenung\Application Data\AVGTOOLBAR
2008-11-26 18:29 . 2008-11-26 18:32 d——– c:\documents and settings\All Users\Application Data\avg8
2008-11-26 18:08 . 2008-11-26 18:08 d——– c:\program files\CCleaner
2008-11-26 18:01 . 2008-11-26 18:01 d——– c:\documents and settings\Dave Schoenung\Application Data\Sammsoft
2008-11-26 18:00 . 2008-11-26 18:00 d——– c:\program files\Advanced Registry Optimizer
2008-11-26 17:19 . 2008-11-26 17:19 d——– c:\documents and settings\All Users\Application Data\TEMP
2008-11-26 16:49 . 2008-11-26 16:49 d——– c:\program files\Common Files\eSellerate
2008-11-26 16:49 . 2008-11-26 16:49 d——– c:\program files\AnswersThatWork
2008-11-26 16:49 . 2007-06-08 12:53 1,753,088 –a—— c:\windows\system32\ExGrid.dll
2008-11-26 16:49 . 2007-04-03 15:51 614,400 –a—— c:\windows\system32\ExButton.dll
2008-11-26 16:49 . 2007-06-05 09:20 602,112 –a—— c:\windows\system32\ExMenu.dll
2008-11-26 16:49 . 2007-06-05 09:19 516,096 –a—— c:\windows\system32\ExTab.dll
2008-11-26 16:49 . 1998-04-23 23:00 368,912 –a—— c:\windows\system32\vbar332.dll
2008-11-26 16:49 . 2005-10-11 13:40 356,352 –a—— c:\windows\system32\eSellerateEngine.dll
2008-11-26 16:49 . 2007-04-03 15:51 307,200 –a—— c:\windows\system32\ExPMenu.dll
2008-11-26 16:49 . 2004-03-09 00:00 124,688 –a—— c:\windows\system32\MSWinSck.ocx
2008-11-26 16:49 . 2005-10-04 07:11 118,784 –a—— c:\windows\system32\eWebControl.dll
2008-11-23 19:53 . 2008-11-23 20:22 d——– C:\virus files
2008-11-17 11:56 . 2008-11-17 11:56 d——– c:\program files\SB
2008-11-17 11:56 . 2008-11-17 12:43 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-15 21:06 . 2008-11-15 21:06 27,904 –a—— c:\windows\system32\drivers\ndisprot.sys
2008-11-15 11:51 . 2008-11-15 11:51 d——– c:\program files\Lavasoft
2008-11-15 11:51 . 2008-11-15 11:52 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-15 11:50 . 2008-11-15 11:50 d——– c:\program files\Common Files\Wise Installation Wizard
2008-11-12 21:57 . 2008-11-27 17:39 d——– C:\TMP
2008-11-12 06:13 . 1998-06-24 13:00 244,024 –a—— c:\windows\system32\MSFLXGRD.OCX
2008-11-12 06:13 . 2005-06-18 10:44 212,240 –a—— c:\windows\system32\richtx32.ocx
2008-11-12 06:13 . 2001-03-13 13:49 140,288 –a—— c:\windows\system32\COMDLG32.OCX
2008-11-12 06:13 . 2004-03-09 13:00 132,880 –a—— c:\windows\system32\MSINET.OCX
2008-11-12 05:55 . 2008-11-12 05:55 d——– c:\documents and settings\Dave Schoenung\Application Data\AdwareAlert
2008-11-12 04:38 . 2008-11-12 04:38 d——– c:\documents and settings\Dave Schoenung\Application Data\Talkback
2008-11-12 04:12 . 2008-11-12 04:38 99,965 –a—— c:\windows\UninstallFirefox.exe
2008-11-12 04:12 . 2008-11-12 04:38 3,233 –a—— c:\windows\mozver.dat
2008-11-12 04:12 . 2008-11-12 04:12 0 –a—— c:\windows\nsreg.dat
2008-11-11 08:44 . 2008-11-11 08:44 d——– c:\program files\Windows Installer Clean Up
2008-11-11 08:28 . 2006-12-05 17:17 240 –a—— c:\windows\myClean.bat
2008-11-11 08:25 . 2008-11-11 08:25 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-16 02:18 90,112 —-a-w c:\windows\DUMP8da9.tmp
2008-11-11 13:43 ——— d—–w c:\program files\MSECACHE
2008-11-10 14:42 721,912 —-a-w c:\documents and settings\Dave Schoenung\gotomypc_428.exe
2008-10-15 22:45 ——— d—–w c:\program files\Foxit Software
2008-10-15 22:42 ——— d—–w c:\program files\Common Files\Adobe
2008-10-02 22:57 ——— d—–w c:\program files\SonicWALL
2008-10-02 22:44 ——— d—–w c:\documents and settings\Dave Schoenung\Application Data\SonicWALL
2008-10-02 22:33 ——— d—–w c:\documents and settings\davent\Application Data\SonicWALL
2008-10-02 22:28 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-02 22:28 ——— d—–w c:\program files\Common Files\Deterministic Networks
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-23 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"AROReminder"="c:\program files\Advanced Registry Optimizer\ARO.exe" [2008-04-09 2135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-22 1392640]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-04-18 227328]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=karna.dat,avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=c:\windows\pss\Windows Desktop Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Dave Schoenung^Start Menu^Programs^Startup^V CAST Music Monitor.lnk]
path=c:\documents and settings\Dave Schoenung\Start Menu\Programs\Startup\V CAST Music Monitor.lnk
backup=c:\windows\pss\V CAST Music Monitor.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
-ra—— 2005-10-06 23:13 176128 c:\program files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
–a—— 2006-06-29 12:13 1032192 c:\program files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
–a—— 2006-08-28 21:57 395776 c:\program files\Dell Support\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
——— 2006-04-06 09:51 49152 c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
–a—— 2005-12-13 02:44 98304 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ModemOnHold]
——— 2003-09-10 02:24 20480 c:\program files\NetWaiting\netwaiting.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-11-10 13:03 36975 c:\program files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2007-08-23 10:21 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
–a—— 2006-03-24 16:30 282624 c:\windows\stsystra.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-26 97928]
R1 RCFOX;SonicWALL IPsec Driver;\??\c:\windows\system32\Drivers\RCFOX.sys [2008-10-02 91136]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-26 231704]
R3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\DRIVERS\rcvpn.sys [2008-10-02 23180]
S3 Ndisprot;ArcNet NDIS Protocol Driver;\??\c:\windows\system32\drivers\Ndisprot.sys [2008-11-15 27904]
S4 TunLprNP;Tun LPR Network Provider; []
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-11-23 c:\windows\Tasks\AdwareAlert Scheduled Scan.job
- c:\program files\AdwareAlert\AdwareAlert.exe []
2008-11-23 c:\windows\Tasks\AdwareAlert Scheduled Scan.job
- c:\program files\AdwareAlert []
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
HKCU-Run-AdwareAlert - c:\program files\AdwareAlert\AdwareAlert.exe
Notify-klogon - (no file)
MSConfigStartUp-Acrobat Assistant 8 - c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Dave Schoenung\Application Data\Mozilla\Firefox\Profiles\sp8vdt1j.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.dffcu.org/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-27 18:26:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSmqct.sys"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1520)
c:\windows\system32\BCMLogon.dll
c:\windows\system32\WLPRNPNT.DLL
.
Completion time: 2008-11-27 18:27:13
ComboFix-quarantined-files.txt 2008-11-27 23:27:11
Pre-Run: 68,341,940,224 bytes free
Post-Run: 68,368,519,168 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
194