combofix log
I cannot get on to this site or any of the links you suggested to get the combofix file from my machine so i had to use another machine.
Had to transfer combofix using my flash drive to the infected machine.
At first it was not working until I remembered reading somewhere if I changed the name slightly it should work. Changing the name to Combo-fix did eventually work.
Here is the log it produced:
ComboFix 08-05-29.1 - Danielle 2008-05-30 12:11:57.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.57 [GMT -4:00]
Running from: C:\Documents and Settings\Danielle\Desktop\Combo-Fix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\d.exe
C:\Program Files\download plugin
C:\Program Files\MyWay
C:\WINDOWS\system32\158117
C:\WINDOWS\system32\clbdll.dll
C:\WINDOWS\system32\clbinit.dll
C:\WINDOWS\system32\drivers\clbdriver.sys
C:\WINDOWS\system32\drivers\Epu83.sys
C:\WINDOWS\system32\ksnhtr.sys
C:\WINDOWS\system32\WinCtrl32.dll
C:\WINDOWS\system32\WinNt32.dll
C:\WINDOWS\system32\WLCtrl32.dll
C:\WINDOWS\system32\ksnhtr.sys . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CLBDRIVER
-------\Legacy_EPU83
-------\Legacy_tcpsr
-------\Service_Epu83
-------\Service_ksnhtr
-------\Service_tcpsr
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-30 )))))))))))))))))))))))))))))))
.
2008-05-29 19:10 . 2004-08-03 22:56 13,312 --a------ C:\WINDOWS\system32\glock32.exe
2008-05-28 23:26 . 2008-05-28 23:26 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-28 19:18 . 2008-05-28 19:18 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-27 16:44 . 2008-05-27 16:44 21,504 --a------ C:\WINDOWS\system32\rtajlss.dll
2008-05-27 09:49 . 2008-05-27 09:58 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-05-26 22:19 . 2008-05-26 22:19 <DIR> d-------- C:\Documents and Settings\Danielle\Application Data\vlc
2008-05-26 22:16 . 2008-05-26 22:16 <DIR> d-------- C:\Program Files\VideoLAN
2008-05-26 21:03 . 2008-05-26 21:05 <DIR> d-------- C:\Program Files\MagicISO Maker v5 4
2008-05-26 18:16 . 2008-05-30 12:23 <DIR> d-------- C:\Program Files\Symantec AntiVirus
2008-05-26 02:17 . 2001-08-17 11:47 4,224 --a------ C:\WINDOWS\system32\beep.sys
2008-05-26 02:16 . 2008-05-30 12:31 68,018 --a------ C:\WINDOWS\system32\ksnhtr.sys
2008-05-26 02:16 . 2008-05-26 02:16 2 --a------ C:\-52465156
2008-05-08 09:53 . 2008-05-08 09:53 51,304 --a------ C:\WINDOWS\system32\drivers\atnt40k.sys
2008-05-08 09:51 . 2008-05-08 09:51 202,827 --a------ C:\WINDOWS\system32\atasnt40.dll
2008-05-03 16:51 . 2008-05-03 16:51 <DIR> d-------- C:\WINDOWS\Can You See What I See
2008-05-03 16:51 . 2008-05-23 13:49 <DIR> d-------- C:\Program Files\Can You See What I See
2008-05-02 20:14 . 2008-05-02 20:14 <DIR> d-------- C:\Documents and Settings\Danielle\Saved Games
2008-05-02 19:36 . 2008-05-02 19:38 <DIR> d-------- C:\Program Files\Dream Day First Home
2008-05-01 18:02 . 2008-05-01 18:02 268 --ah----- C:\sqmdata03.sqm
2008-05-01 18:02 . 2008-05-01 18:02 244 --ah----- C:\sqmnoopt03.sqm
2008-04-29 19:18 . 2008-04-29 19:18 <DIR> d-------- C:\Program Files\MSECache
2008-04-27 15:16 . 2008-04-27 15:16 268 --ah----- C:\sqmdata02.sqm
2008-04-27 15:16 . 2008-04-27 15:16 244 --ah----- C:\sqmnoopt02.sqm
2008-04-20 22:11 . 2008-04-20 22:11 244 --ah----- C:\sqmnoopt01.sqm
2008-04-20 22:11 . 2008-04-20 22:11 232 --ah----- C:\sqmdata01.sqm
2008-04-13 23:19 . 2008-04-13 23:19 116 --a------ C:\WINDOWS\wininit.ini
2008-04-13 20:00 . 2008-05-26 18:31 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-13 20:00 . 2008-05-26 18:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-09 16:06 . 2008-04-15 20:42 <DIR> d-------- C:\Program Files\Shareaza Applications
2008-04-09 16:06 . 2006-11-12 11:39 483,328 --a------ C:\WINDOWS\system32\actskn45.ocx
2008-04-08 19:42 . 2008-04-08 19:42 <DIR> d-------- C:\Documents and Settings\Danielle\Application Data\Motive
2008-04-07 22:11 . 2008-04-07 22:11 26,112 --a------ C:\WINDOWS\system32\drivers\nchssvad.sys
2008-04-07 17:52 . 2008-04-07 17:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MotiveSysIDs
2008-04-07 17:50 . 2008-04-07 17:50 <DIR> d-------- C:\WINDOWS\Motive
2008-04-07 17:44 . 2008-04-08 19:42 <DIR> d-------- C:\Program Files\TSTT Quick Assist
2008-04-07 17:44 . 2008-04-07 17:46 <DIR> d-------- C:\Program Files\Motive
2008-04-07 17:28 . 2008-04-09 08:12 <DIR> d-------- C:\Program Files\Common Files\Motive
2008-04-07 17:28 . 2008-04-07 17:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Motive
2008-04-07 17:28 . 2005-04-05 18:20 69,632 --a------ C:\WINDOWS\system32\MCCDevice.dll
2008-04-07 17:28 . 2005-03-25 19:27 6,048 --a------ C:\WINDOWS\system32\MCC16.dll
2008-04-07 17:27 . 2003-02-28 16:34 313,856 --a------ C:\WINDOWS\system32\dx3j.dll
2008-04-07 17:27 . 2003-02-28 18:26 171,280 --a------ C:\WINDOWS\system32\jit.dll
2008-04-07 17:27 . 2003-02-28 18:26 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2008-04-07 17:27 . 2003-02-28 18:26 46,352 --a------ C:\WINDOWS\setdebug.exe
2008-04-07 17:27 . 2003-02-28 16:54 7,315 --a------ C:\WINDOWS\system32\javasup.vxd
2008-04-07 17:27 . 2003-02-28 16:35 6,550 --a------ C:\WINDOWS\jautoexp.dat
2008-04-07 17:25 . 2002-02-14 03:53 6,345 -ra------ C:\WINDOWS\system32\DevMngr.vxd
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-27 01:18 --------- d-----w C:\Program Files\dvdSanta
2008-05-26 22:19 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-26 22:17 --------- d-----w C:\Program Files\Symantec
2008-05-26 22:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-26 06:32 --------- d-----w C:\Program Files\FlashGet
2008-05-26 06:30 --------- d-----w C:\Documents and Settings\Danielle\Application Data\uTorrent
2008-05-22 20:52 --------- d-----w C:\Program Files\Samsung
2008-05-22 16:27 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-22 16:20 --------- d-----w C:\Documents and Settings\Danielle\Application Data\AdobeUM
2008-04-08 02:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-04-08 02:17 --------- d-----w C:\Program Files\NCH Swift Sound
2008-04-08 02:17 --------- d-----w C:\Documents and Settings\Danielle\Application Data\NCH Swift Sound
2008-04-07 21:50 1,096 ----a-w C:\Program Files\DOWNLOAD_INSTALL.LOG
2008-04-07 21:27 155,995 ----a-w C:\WINDOWS\java\Packages\7ZV3NDF1.ZIP
2007-12-13 01:06 836 -c--a-w C:\Documents and Settings\Danielle\Application Data\ViewerApp.dat
2005-03-28 20:29 56 -csh--r C:\WINDOWS\system32\FC31D8CBC2.sys
2005-03-28 20:29 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
------- Sigcheck -------
2005-02-18 14:22 502272 6225f14b8ce08ccba8b25ad27843c674 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{598F4775-6FB6-477B-9842-E0426824E077}]
C:\DOCUME~1\Danielle\LOCALS~1\Temp\~DP12.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 22:56 15360]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2004-07-26 19:14 1867776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 04:04 59392]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-12-09 20:19 188416]
"DataLayer"="C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE" [2004-06-07 12:07 1097728]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE" [2004-05-21 10:41 148992]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"CapFax"="C:\Program Files\Classic PhoneTools\CapFax.EXE" [2001-12-10 17:34 20739]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48 36975]
"PC Suite for Smartphones"="C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" [2006-04-25 13:09 487424]
"TSTTCCU_550"="C:\Program Files\TSTT\CCU550\Bin\CMTNF5500D.exe" [2005-07-18 02:23 208896]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17 159744]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-14 23:38 155648]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [ ]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 15:21 57344]
"Motive SmartBridge"="C:\PROGRA~1\TSTTQU~1\SMARTB~1\MotiveSB.exe" [2006-06-27 14:03 458839]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 16:44 66680]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-03-12 15:18 124128]
"Glock Suite 1.1"="C:\WINDOWS\system32\glock32.exe" [2004-08-03 22:56 13312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rtajlss]
rtajlss.dll 2008-05-27 16:44 21504 C:\WINDOWS\system32\rtajlss.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
"vidc.xvid"= xvid.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ljo61.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\slt31.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\WinMX\\WinMX.exe"=
"C:\\Program Files\\TSTT\\CCU550\\Bin\\CMOCCU.exe"=
"C:\\Program Files\\Intuwave\\Shared\\mRouterRuntime\\mRouterRuntime.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
R3 zebrceb;Sony Ericsson Cable Emulation Bus (WDM);C:\WINDOWS\system32\DRIVERS\zebrceb.sys [2006-04-21 10:21]
S0 ljo61;ljo61;C:\WINDOWS\system32\Drivers\ljO61.sys []
S0 slt31;slt31;C:\WINDOWS\system32\Drivers\slT31.sys []
S3 cmo_bus;Data Modem @ CDMA Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\cmo_bus.sys [2005-08-16 21:59]
S3 cmo_mdfl;Data Modem @ CDMA Filter;C:\WINDOWS\system32\DRIVERS\cmo_mdfl.sys [2005-08-16 22:02]
S3 cmo_mdm;Data Modem @ CDMA Drivers;C:\WINDOWS\system32\DRIVERS\cmo_mdm.sys [2005-08-16 22:02]
S3 SE31bus;Sony Ericsson Device 049 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE31bus.sys [2006-05-01 13:56]
S3 SE31mdfl;Sony Ericsson Device 049 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE31mdfl.sys [2006-05-01 13:57]
S3 SE31mdm;Sony Ericsson Device 049 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE31mdm.sys [2006-05-01 13:57]
S3 SE31mgmt;Sony Ericsson Device 049 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE31mgmt.sys [2006-05-01 07:58]
S3 se31nd5;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (NDIS);C:\WINDOWS\system32\DRIVERS\se31nd5.sys [2006-05-01 07:56]
S3 SE31obex;Sony Ericsson Device 049 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE31obex.sys [2006-05-01 07:59]
S3 se31unic;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (WDM);C:\WINDOWS\system32\DRIVERS\se31unic.sys [2006-05-01 07:56]
S3 Slnt7554;USB Soft Modem Driver;C:\WINDOWS\system32\DRIVERS\slnt7554.sys [2004-08-03 22:41]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2006-04-17 03:23]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2006-04-17 03:23]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2006-04-17 03:23]
S3 zebrbus;Sony Ericsson Composite Device driver;C:\WINDOWS\system32\DRIVERS\zebrbus.sys [2006-04-21 10:21]
S3 zebrmdfl;Sony Ericsson Modem Filter;C:\WINDOWS\system32\DRIVERS\zebrmdfl.sys [2006-04-21 10:22]
S3 zebrmdm;Sony Ericsson Port (WDM);C:\WINDOWS\system32\DRIVERS\zebrmdm.sys [2006-04-21 10:22]
S3 zebrmdmc;Sony Ericsson mRouter Port (WDM);C:\WINDOWS\system32\DRIVERS\zebrmdmc.sys [2006-04-21 10:22]
S3 zebrsce;Sony Ericsson PC-Connect Port;C:\WINDOWS\system32\DRIVERS\zebrsce.sys [2006-04-21 10:22]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01a15bc8-8be9-11db-8eed-e1601f7c6e16}]
\shell\verb1\command - desktop.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{13ac8211-8dab-11dc-8f91-e615ba981d1e}]
\shell\verb1\command - desktop.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3abc4eb0-be41-11d9-8d06-0050dac47019}]
\shell\PlayWithPowerDVD\Command - "C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" "%l"
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-30 12:27:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\rtajlss.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\ehome\ehRecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\devldr32.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-05-30 12:39:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-30 16:39:13
Pre-Run: 14,284,910,592 bytes free
Post-Run: 14,987,919,360 bytes free
222 --- E O F --- 2008-05-26 22:21:18