Our pc got infected with 'XP Anti-Spyware' on Friday. *I was able to find and remove that from the files and registry entries. *Still have numerious problems such as cannot access windowsupdate.com or update.microsoft.com. *I removed SpyBot in Aug-2010 due to performance concerns and perceived incompatibilities with McAfee. *I reinstalled and ran SpyBot again on Saturday. *It detected and indicated that it fixed several problems however there are no current checklogs. *Resident TeaTimer has been disabled. *I tried running MSRT and got a blue-screen. *I am running another McAfee Scan since I've paid for the product but I don't expect much from it at this time. *I'm also running OneCare safety scan. *
I have run ERUNT and DSS, here is the DSS log and several lines from SpyBot reports. *Thanks for any assistance. *
***********Doug & Suzanne McNabb
DSS.txt
.
DDS (Ver_11-03-05.01) - NTFSx86 *
Run by Suzanne at 21:19:07.57 on Sat 03/26/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional *5.1.2600.3.1252.1.1033.18.2038.1057 [GMT -4:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\System32\svchost.exe -k itlsvc
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Program Files\McAfee Online Backup\MOBKbackup.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Online Backup\OnlineBackup.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\McAfee Online Backup\MOBKstat.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
C:\Documents and Settings\Suzanne\My Documents\Downloaded Program Updates\dds.com
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.goodsearch.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20101104090656.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: att.net Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [OnlineBackupScheduler] c:\program files\online backup\OnlineBackup.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [Norton Ghost 10.0] "c:\program files\norton ghost\agent\GhostTray.exe"
mRun: [basicsmssmenu] "c:\program files\seagate\basics\basics status\MaxMenuMgrBasics.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee online backup\MOBKstat.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: musicmatch.com\online
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6886.cab
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} - hxxp://vsp.closetmaid.com/vsp/cmaidctl_vsp.closetmaid.com_downloader.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} - hxxps://pattcw.att.motive.com/wizlet/DSLActivation/static/installer/ATTInternetInstaller.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: fN9/ - itlnfw32.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\615\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
Notify: itlnfw32 - itlnfw32.dll
Notify: itlntfy - itlnfw32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
Hosts: 127.0.0.1 * *www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-16 386840]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-5-4 84072]
R1 MOBKFilter;MOBKFilter;c:\windows\system32\drivers\MOBK.sys [2011-1-17 54776]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCEVTMGR.EXE [2004-12-13 198248]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSETMGR.EXE [2004-12-13 181864]
R2 itlperf;Intel CPU;c:\windows\system32\svchost.exe -k itlsvc [2005-8-16 14336]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-3-30 210216]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-5-4 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-5-4 271480]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-5-4 271480]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-5-4 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-5-4 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-5-4 141792]
R2 MOBKbackup;McAfee Online Backup;c:\program files\mcafee online backup\MOBKbackup.exe [2010-4-13 229688]
R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2008-1-13 822424]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-5-4 55840]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-3-30 152960]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-3-30 52104]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-5-4 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-5-4 88544]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\CCPWDSVC.EXE [2004-12-13 79464]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-5-4 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-5-4 84264]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-3-30 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-3-30 40552]
.
=============== Created Last 30 ================
.
2011-03-27 00:37:16 * *-------- * *d-----w- * *C:\VundoFix Backups
2011-03-25 23:55:32 * *146432 * *----a-w- * *c:\windows\regedit.com
2011-03-25 12:23:02 * *4199768 * *----a-w- * *c:\windows\system32\cdintf400.dll
2011-03-24 17:49:53 * *53248 * *----a-w- * *c:\windows\system32\6to4v32.dll
2011-03-24 17:49:45 * *34816 * *----a-w- * *c:\windows\system32\itlnfw32.dll
2011-03-24 17:49:45 * *216064 * *----a-w- * *c:\windows\system32\itlpfw32.dll
2011-03-22 06:01:34 * *5943120 * *----a-w- * *c:\docume~1\alluse~1\applic~1\microsoft\windows defender\definition updates\{2b19e4f6-b2c8-4dbc-9641-5cb9512a9453}\mpengine.dll
2011-03-12 01:30:12 * *244416 * *----a-w- * *c:\windows\system32\Msflxgrd.ocx
2011-03-12 01:30:12 * *203976 * *----a-w- * *c:\windows\system32\RICHTX32.OCX
2011-03-12 01:29:29 * *-------- * *d-----w- * *c:\docume~1\suzanne\applic~1\PCHC
2011-03-11 23:47:03 * *-------- * *d-----w- * *c:\program files\iPod
2011-03-11 23:46:46 * *-------- * *d-----w- * *c:\program files\iTunes
2011-03-09 21:40:17 * *-------- * *d-----w- * *c:\program files\ATT
2011-03-09 21:26:24 * *-------- * *d-----w- * *c:\docume~1\suzanne\locals~1\applic~1\Yahoo
2011-03-09 21:25:25 * *-------- * *d-----w- * *c:\docume~1\suzanne\locals~1\applic~1\ATTYToolbar
2011-03-09 21:25:23 * *-------- * *d-----w- * *c:\docume~1\alluse~1\applic~1\ATTYToolbar
2011-03-09 21:25:05 * *-------- * *d-----w- * *c:\program files\Yahoo!
2011-03-08 18:11:18 * *-------- * *d-----w- * *c:\program files\ATT-HSI
2011-03-08 18:10:59 * *-------- * *d-----w- * *c:\program files\common files\Motive
.
==================== Find3M *====================
.
2011-02-18 21:36:58 * *4184352 * *----a-w- * *c:\windows\system32\usbaaplrc.dll
2011-02-04 22:48:32 * *456192 * *----a-w- * *c:\windows\system32\encdec.dll
2011-02-04 22:48:30 * *291840 * *----a-w- * *c:\windows\system32\sbe.dll
2011-02-02 22:11:20 * *222080 * *------w- * *c:\windows\system32\MpSigStub.exe
2011-02-02 07:58:35 * *2067456 * *----a-w- * *c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 * *677888 * *----a-w- * *c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 * *439296 * *----a-w- * *c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 * *290048 * *----a-w- * *c:\windows\system32\atmfd.dll
2010-12-31 13:10:33 * *1854976 * *----a-w- * *c:\windows\system32\win32k.sys
.
=================== ROOTKIT *====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: Intel___ rev.1.0. -> Harddisk0\DR0 -> \Device\Ide\iaStor0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x89C6D439]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x89c737d0]; MOV EAX, [0x89c7384c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; *}
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8A588030]
3 CLASSPNP[0xBA0E8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x89C38540]
\Driver\iastor[0x8A58FDC8] -> IRP_MJ_CREATE -> 0x89C6D439
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x147; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; *}
detected disk devices:
\Device\Ide\IAAStorageDevice-0 -> \??\IDE#DiskARRAY1.0.00_U#4&38ab82b6&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user != kernel MBR !!!
sectors 156249086 (+255): user != kernel
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 21:21:55.51 ===============
Checks.110310-0130.log
10.03.2011 01:30:56 - ##### check started #####
10.03.2011 01:30:56 - ### Version: 1.6.2
10.03.2011 01:30:56 - ### Date: 3/10/2011 1:30:56 AM
10.03.2011 01:31:01 - ##### checking bots #####
Run Entry History.txt
When: ******2011-03-26 12:44:33
Who: *******C:\Program Files\Spybot - Search & Destroy\advcheck.dll
Run Entry: *Spybot - Search & Destroy
Executable: "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
Reason: ****scan result requested reboot (allowed by user feedback)
Update downloads.log
<--earlier entries deleted-->
8/25/2010 12:57:16 AM Downloaded update info file. (http://www.safer-networking.org/updates/spybotsd.ini)
8/25/2010 12:57:35 AM downloaded update Detection rules: iPhone
8/25/2010 12:57:35 AM *- URL: http://imp.betanews.com/updates/files/includes.iPhone.zip
8/25/2010 12:57:35 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.iPhone.zip
8/25/2010 12:57:36 AM downloaded update Detection rules: Keyloggers
8/25/2010 12:57:36 AM *- URL: http://imp.betanews.com/updates/files/includes.keyloggers.zip
8/25/2010 12:57:36 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.keyloggers.zip
8/25/2010 12:57:38 AM downloaded update Detection rules: Malware
8/25/2010 12:57:38 AM *- URL: http://imp.betanews.com/updates/files/includes.malware.zip
8/25/2010 12:57:38 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.malware.zip
8/25/2010 12:57:40 AM downloaded update Detection rules: PUPS
8/25/2010 12:57:40 AM *- URL: http://imp.betanews.com/updates/files/includes.pups.zip
8/25/2010 12:57:40 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.pups.zip
8/25/2010 12:57:41 AM downloaded update Detection rules: Spybots
8/25/2010 12:57:41 AM *- URL: http://imp.betanews.com/updates/files/includes.spybots.zip
8/25/2010 12:57:41 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.spybots.zip
8/25/2010 12:57:44 AM downloaded update Detection rules: Supplemental
8/25/2010 12:57:44 AM *- URL: http://imp.betanews.com/updates/files/supplemental.zip
8/25/2010 12:57:44 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\supplemental.zip
8/25/2010 12:57:46 AM downloaded update Detection rules: Trojans
8/25/2010 12:57:46 AM *- URL: http://imp.betanews.com/updates/files/includes.trojans.zip
8/25/2010 12:57:46 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.trojans.zip
8/25/2010 12:58:01 AM downloaded update Detection rules: Update
8/25/2010 12:58:01 AM *- URL: http://imp.betanews.com/updates/files/includes.zip
8/25/2010 12:58:01 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.zip
3/26/2011 12:07:21 PM Downloaded update info file. (http://www.safer-networking.org/updates/spybotsd.ini)
3/26/2011 12:07:55 PM downloaded update Advanced detection library 1.6.5
3/26/2011 12:07:55 PM *- URL: http://spybot.xploredownload.com/updates/files/advcheck165.zip
3/26/2011 12:07:55 PM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\advcheck165.zip
3/26/2011 12:07:56 PM downloaded update English descriptions
3/26/2011 12:07:56 PM *- URL: http://spybot.xploredownload.com/updates/files/desc.english.zip
3/26/2011 12:07:56 PM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\desc.english.zip
3/26/2011 12:07:57 PM downloaded update Immunization database
3/26/2011 12:07:57 PM *- URL: http://spybot.xploredownload.com/updates/files/clsid.zip
3/26/2011 12:07:57 PM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\clsid.zip
3/26/2011 12:07:59 PM downloaded update Startup info
3/26/2011 12:07:59 PM *- URL: http://spybot.xploredownload.com/updates/files/startup.zip
3/26/2011 12:07:59 PM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\startup.zip
3/26/2011 12:08:01 PM downloaded update TeaTimer update 1.6.6
3/26/2011 12:08:01 PM *- URL: http://spybot.xploredownload.com/updates/files/teatimer166.zip
3/26/2011 12:08:01 PM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\teatimer166.zip
3/26/2011 9:24:55 PM Downloaded update info file. (http://www.safer-networking.org/updates/spybotsd.ini)
3/27/2011 10:17:08 AM Downloaded update info file. (http://www.safer-networking.org/updates/spybotsd.ini)
Btw, I was unable to post the note through the infected pc so I had to make this post from another machine.
Here's the attach.zip file.
I have run ERUNT and DSS, here is the DSS log and several lines from SpyBot reports. *Thanks for any assistance. *
***********Doug & Suzanne McNabb
DSS.txt
.
DDS (Ver_11-03-05.01) - NTFSx86 *
Run by Suzanne at 21:19:07.57 on Sat 03/26/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional *5.1.2600.3.1252.1.1033.18.2038.1057 [GMT -4:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\System32\svchost.exe -k itlsvc
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Program Files\McAfee Online Backup\MOBKbackup.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Online Backup\OnlineBackup.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\McAfee Online Backup\MOBKstat.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
C:\Documents and Settings\Suzanne\My Documents\Downloaded Program Updates\dds.com
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.goodsearch.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20101104090656.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: att.net Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [OnlineBackupScheduler] c:\program files\online backup\OnlineBackup.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [Norton Ghost 10.0] "c:\program files\norton ghost\agent\GhostTray.exe"
mRun: [basicsmssmenu] "c:\program files\seagate\basics\basics status\MaxMenuMgrBasics.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee online backup\MOBKstat.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: musicmatch.com\online
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6886.cab
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} - hxxp://vsp.closetmaid.com/vsp/cmaidctl_vsp.closetmaid.com_downloader.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} - hxxps://pattcw.att.motive.com/wizlet/DSLActivation/static/installer/ATTInternetInstaller.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: fN9/ - itlnfw32.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\615\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
Notify: itlnfw32 - itlnfw32.dll
Notify: itlntfy - itlnfw32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
Hosts: 127.0.0.1 * *www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-16 386840]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-5-4 84072]
R1 MOBKFilter;MOBKFilter;c:\windows\system32\drivers\MOBK.sys [2011-1-17 54776]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCEVTMGR.EXE [2004-12-13 198248]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSETMGR.EXE [2004-12-13 181864]
R2 itlperf;Intel CPU;c:\windows\system32\svchost.exe -k itlsvc [2005-8-16 14336]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-3-30 210216]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-5-4 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-5-4 271480]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-5-4 271480]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-5-4 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-5-4 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-5-4 141792]
R2 MOBKbackup;McAfee Online Backup;c:\program files\mcafee online backup\MOBKbackup.exe [2010-4-13 229688]
R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2008-1-13 822424]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-5-4 55840]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-3-30 152960]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-3-30 52104]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-5-4 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-5-4 88544]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\CCPWDSVC.EXE [2004-12-13 79464]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-5-4 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-5-4 84264]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-3-30 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-3-30 40552]
.
=============== Created Last 30 ================
.
2011-03-27 00:37:16 * *-------- * *d-----w- * *C:\VundoFix Backups
2011-03-25 23:55:32 * *146432 * *----a-w- * *c:\windows\regedit.com
2011-03-25 12:23:02 * *4199768 * *----a-w- * *c:\windows\system32\cdintf400.dll
2011-03-24 17:49:53 * *53248 * *----a-w- * *c:\windows\system32\6to4v32.dll
2011-03-24 17:49:45 * *34816 * *----a-w- * *c:\windows\system32\itlnfw32.dll
2011-03-24 17:49:45 * *216064 * *----a-w- * *c:\windows\system32\itlpfw32.dll
2011-03-22 06:01:34 * *5943120 * *----a-w- * *c:\docume~1\alluse~1\applic~1\microsoft\windows defender\definition updates\{2b19e4f6-b2c8-4dbc-9641-5cb9512a9453}\mpengine.dll
2011-03-12 01:30:12 * *244416 * *----a-w- * *c:\windows\system32\Msflxgrd.ocx
2011-03-12 01:30:12 * *203976 * *----a-w- * *c:\windows\system32\RICHTX32.OCX
2011-03-12 01:29:29 * *-------- * *d-----w- * *c:\docume~1\suzanne\applic~1\PCHC
2011-03-11 23:47:03 * *-------- * *d-----w- * *c:\program files\iPod
2011-03-11 23:46:46 * *-------- * *d-----w- * *c:\program files\iTunes
2011-03-09 21:40:17 * *-------- * *d-----w- * *c:\program files\ATT
2011-03-09 21:26:24 * *-------- * *d-----w- * *c:\docume~1\suzanne\locals~1\applic~1\Yahoo
2011-03-09 21:25:25 * *-------- * *d-----w- * *c:\docume~1\suzanne\locals~1\applic~1\ATTYToolbar
2011-03-09 21:25:23 * *-------- * *d-----w- * *c:\docume~1\alluse~1\applic~1\ATTYToolbar
2011-03-09 21:25:05 * *-------- * *d-----w- * *c:\program files\Yahoo!
2011-03-08 18:11:18 * *-------- * *d-----w- * *c:\program files\ATT-HSI
2011-03-08 18:10:59 * *-------- * *d-----w- * *c:\program files\common files\Motive
.
==================== Find3M *====================
.
2011-02-18 21:36:58 * *4184352 * *----a-w- * *c:\windows\system32\usbaaplrc.dll
2011-02-04 22:48:32 * *456192 * *----a-w- * *c:\windows\system32\encdec.dll
2011-02-04 22:48:30 * *291840 * *----a-w- * *c:\windows\system32\sbe.dll
2011-02-02 22:11:20 * *222080 * *------w- * *c:\windows\system32\MpSigStub.exe
2011-02-02 07:58:35 * *2067456 * *----a-w- * *c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 * *677888 * *----a-w- * *c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 * *439296 * *----a-w- * *c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 * *290048 * *----a-w- * *c:\windows\system32\atmfd.dll
2010-12-31 13:10:33 * *1854976 * *----a-w- * *c:\windows\system32\win32k.sys
.
=================== ROOTKIT *====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: Intel___ rev.1.0. -> Harddisk0\DR0 -> \Device\Ide\iaStor0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x89C6D439]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x89c737d0]; MOV EAX, [0x89c7384c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; *}
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8A588030]
3 CLASSPNP[0xBA0E8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x89C38540]
\Driver\iastor[0x8A58FDC8] -> IRP_MJ_CREATE -> 0x89C6D439
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x147; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; *}
detected disk devices:
\Device\Ide\IAAStorageDevice-0 -> \??\IDE#DiskARRAY1.0.00_U#4&38ab82b6&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user != kernel MBR !!!
sectors 156249086 (+255): user != kernel
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 21:21:55.51 ===============
Checks.110310-0130.log
10.03.2011 01:30:56 - ##### check started #####
10.03.2011 01:30:56 - ### Version: 1.6.2
10.03.2011 01:30:56 - ### Date: 3/10/2011 1:30:56 AM
10.03.2011 01:31:01 - ##### checking bots #####
Run Entry History.txt
When: ******2011-03-26 12:44:33
Who: *******C:\Program Files\Spybot - Search & Destroy\advcheck.dll
Run Entry: *Spybot - Search & Destroy
Executable: "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
Reason: ****scan result requested reboot (allowed by user feedback)
Update downloads.log
<--earlier entries deleted-->
8/25/2010 12:57:16 AM Downloaded update info file. (http://www.safer-networking.org/updates/spybotsd.ini)
8/25/2010 12:57:35 AM downloaded update Detection rules: iPhone
8/25/2010 12:57:35 AM *- URL: http://imp.betanews.com/updates/files/includes.iPhone.zip
8/25/2010 12:57:35 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.iPhone.zip
8/25/2010 12:57:36 AM downloaded update Detection rules: Keyloggers
8/25/2010 12:57:36 AM *- URL: http://imp.betanews.com/updates/files/includes.keyloggers.zip
8/25/2010 12:57:36 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.keyloggers.zip
8/25/2010 12:57:38 AM downloaded update Detection rules: Malware
8/25/2010 12:57:38 AM *- URL: http://imp.betanews.com/updates/files/includes.malware.zip
8/25/2010 12:57:38 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.malware.zip
8/25/2010 12:57:40 AM downloaded update Detection rules: PUPS
8/25/2010 12:57:40 AM *- URL: http://imp.betanews.com/updates/files/includes.pups.zip
8/25/2010 12:57:40 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.pups.zip
8/25/2010 12:57:41 AM downloaded update Detection rules: Spybots
8/25/2010 12:57:41 AM *- URL: http://imp.betanews.com/updates/files/includes.spybots.zip
8/25/2010 12:57:41 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.spybots.zip
8/25/2010 12:57:44 AM downloaded update Detection rules: Supplemental
8/25/2010 12:57:44 AM *- URL: http://imp.betanews.com/updates/files/supplemental.zip
8/25/2010 12:57:44 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\supplemental.zip
8/25/2010 12:57:46 AM downloaded update Detection rules: Trojans
8/25/2010 12:57:46 AM *- URL: http://imp.betanews.com/updates/files/includes.trojans.zip
8/25/2010 12:57:46 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.trojans.zip
8/25/2010 12:58:01 AM downloaded update Detection rules: Update
8/25/2010 12:58:01 AM *- URL: http://imp.betanews.com/updates/files/includes.zip
8/25/2010 12:58:01 AM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\includes.zip
3/26/2011 12:07:21 PM Downloaded update info file. (http://www.safer-networking.org/updates/spybotsd.ini)
3/26/2011 12:07:55 PM downloaded update Advanced detection library 1.6.5
3/26/2011 12:07:55 PM *- URL: http://spybot.xploredownload.com/updates/files/advcheck165.zip
3/26/2011 12:07:55 PM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\advcheck165.zip
3/26/2011 12:07:56 PM downloaded update English descriptions
3/26/2011 12:07:56 PM *- URL: http://spybot.xploredownload.com/updates/files/desc.english.zip
3/26/2011 12:07:56 PM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\desc.english.zip
3/26/2011 12:07:57 PM downloaded update Immunization database
3/26/2011 12:07:57 PM *- URL: http://spybot.xploredownload.com/updates/files/clsid.zip
3/26/2011 12:07:57 PM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\clsid.zip
3/26/2011 12:07:59 PM downloaded update Startup info
3/26/2011 12:07:59 PM *- URL: http://spybot.xploredownload.com/updates/files/startup.zip
3/26/2011 12:07:59 PM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\startup.zip
3/26/2011 12:08:01 PM downloaded update TeaTimer update 1.6.6
3/26/2011 12:08:01 PM *- URL: http://spybot.xploredownload.com/updates/files/teatimer166.zip
3/26/2011 12:08:01 PM *- Local file: C:\Program Files\Spybot - Search & Destroy\Updates\teatimer166.zip
3/26/2011 9:24:55 PM Downloaded update info file. (http://www.safer-networking.org/updates/spybotsd.ini)
3/27/2011 10:17:08 AM Downloaded update info file. (http://www.safer-networking.org/updates/spybotsd.ini)
Btw, I was unable to post the note through the infected pc so I had to make this post from another machine.
Here's the attach.zip file.