Hi,
I ran ComboFix in regular mode, here is the log:
ComboFix 08-05-07.2 - Robin 2008-05-14 8:26:29.10 - NTFSx86
Running from: C:\Combo-Fix.exe
Command switches used :: E:\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\Drivers\beep.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Drivers\beep.sys
.
((((((((((((((((((((((((( Files Created from 2008-04-14 to 2008-05-14 )))))))))))))))))))))))))))))))
.
2008-05-14 08:25 . 2008-05-14 08:26 <DIR> d-------- C:\WINDOWS\Drivers
2008-05-13 18:34 . 2008-05-13 18:34 <DIR> d-------- C:\Program Files\ZoneAlarmSB
2008-05-13 18:31 . 2008-05-13 18:31 <DIR> d-------- C:\Program Files\Zone Labs
2008-05-13 18:31 . 2008-05-13 18:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-05-13 18:29 . 2008-05-14 08:24 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-05-12 13:52 . 2008-05-12 13:52 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-12 13:52 . 2008-05-12 13:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-12 12:52 . 2008-05-13 02:52 206 --a------ C:\Documents and Settings\Robin\delself.bat
2008-05-08 18:07 . 2003-08-01 15:17 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\MSN6
2008-05-08 18:07 . 2003-08-01 16:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-05-08 18:07 . 2008-05-08 18:07 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-08 18:07 . 2008-05-13 18:00 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-05-08 16:22 . 2008-05-09 16:05 1,850,852 --a------ C:\Combo-Fix.exe
2008-05-08 11:12 . 2008-05-08 11:12 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-08 11:12 . 2008-05-08 11:12 <DIR> d-------- C:\Documents and Settings\Robin\Application Data\Malwarebytes
2008-05-08 11:12 . 2008-05-08 11:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-08 11:12 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-08 11:12 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-04-29 02:29 . 2008-04-29 02:29 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-04-29 01:48 . 2008-04-29 01:48 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-29 00:59 . 2008-05-09 00:39 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-29 00:26 . 2008-04-29 00:26 0 --a------ C:\winamp.ini
2008-04-29 00:22 . 2008-05-09 00:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-29 06:03 --------- d-----w C:\Documents and Settings\Robin\Application Data\Symantec
2008-04-29 05:51 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-29 05:49 --------- d-----w C:\Program Files\Symantec
2008-04-29 05:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-14 02:24 4,608 ----a-w C:\WINDOWS\system32\carpserv.exe
2008-04-14 02:24 28,672 ----a-w C:\WINDOWS\system32\ati2mdxx.exe
2008-04-14 00:21 --------- d-----w C:\Program Files\QuickTime
2008-04-14 00:21 --------- d-----w C:\Program Files\Apoint
2008-04-03 02:07 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-04-03 02:07 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
.
Files Infected - Win32.Agent.zb
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\Program Files\QuickTime\qttask.exe
c:\program files\support.com\client\bin\tgcmd.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
.
((((((((((((((((((((((((((((( snapshot@2008-05-09_16.15.32.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-09 21:12:42 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-13 23:36:36 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2005-05-24 17:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-04-03 02:07:36 796,048 ----a-w C:\WINDOWS\system32\libeay32_0.9.6l.dll
+ 2004-04-27 10:40:52 11,264 ----a-w C:\WINDOWS\system32\SpOrder.dll
+ 2008-04-03 02:07:40 83,432 ----a-w C:\WINDOWS\system32\vsdata.dll
+ 2008-04-03 02:08:00 394,952 ----a-w C:\WINDOWS\system32\vsdatant.sys
+ 2008-04-03 02:07:40 157,160 ----a-w C:\WINDOWS\system32\vsinit.dll
+ 2008-04-03 02:07:40 103,912 ----a-w C:\WINDOWS\system32\vsmonapi.dll
+ 2008-04-03 02:07:40 275,944 ----a-w C:\WINDOWS\system32\vspubapi.dll
+ 2008-04-03 02:07:42 71,144 ----a-w C:\WINDOWS\system32\vsregexp.dll
+ 2008-04-03 02:07:42 472,552 ----a-w C:\WINDOWS\system32\vsutil.dll
+ 2008-04-03 02:07:42 46,568 ----a-w C:\WINDOWS\system32\vswmi.dll
+ 2008-04-03 02:07:42 99,816 ----a-w C:\WINDOWS\system32\vsxml.dll
+ 2008-04-03 02:07:44 83,432 ----a-w C:\WINDOWS\system32\zlcomm.dll
+ 2008-04-03 02:07:44 71,144 ----a-w C:\WINDOWS\system32\zlcommdb.dll
+ 2008-05-13 23:34:49 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
+ 2008-04-03 02:07:32 370,208 ----a-w C:\WINDOWS\system32\ZoneLabs\av.dll
+ 2007-05-31 06:03:30 65,248 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\aphish.dat
+ 2006-06-30 20:47:36 21,568 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\avcmhk4.dll
+ 2007-05-31 06:03:30 1,628 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\pdmkl.dat
+ 2007-05-31 06:03:16 77,824 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHComm.dll
+ 2007-05-31 06:03:16 110,592 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHrule.dll
+ 2007-05-31 06:03:16 331,776 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHUM.dll
+ 2007-05-31 06:03:16 38,400 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\FSSync.dll
+ 2006-09-20 05:12:14 208,960 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\inv.dll
+ 2007-12-03 20:53:58 282,624 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\kave.dll
+ 2007-07-19 21:10:32 186,128 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\klif_32.sys
+ 2006-12-20 00:13:52 1,093,632 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\libeay32.dll
+ 2007-05-31 06:03:20 548,864 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcp80.dll
+ 2007-05-31 06:03:20 626,688 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcr80.dll
+ 2007-05-31 06:03:18 184,320 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\prloader.dll
+ 2007-05-31 06:03:22 90,112 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\prremote.dll
+ 2007-12-03 20:53:58 139,264 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
+ 2006-12-20 00:13:52 200,704 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ssleay32.dll
+ 2008-04-03 02:07:32 99,816 ----a-w C:\WINDOWS\system32\ZoneLabs\camupd.dll
+ 2004-01-30 18:35:08 813,568 ----a-w C:\WINDOWS\system32\ZoneLabs\dbghelp.dll
+ 2008-04-03 02:07:34 128,480 ----a-w C:\WINDOWS\system32\ZoneLabs\fbl.dll
+ 2008-04-03 02:07:34 38,376 ----a-w C:\WINDOWS\system32\ZoneLabs\featuremap.dll
+ 2008-04-03 02:07:34 321,016 ----a-w C:\WINDOWS\system32\ZoneLabs\imsecure.dll
+ 2008-04-03 02:08:02 288,144 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\ConfigWizard.zip.dll
+ 2008-04-03 02:08:02 152,976 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\licenseui.zip.dll
+ 2008-04-03 02:08:02 26,000 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zlsvc.zip.dll
+ 2008-04-03 02:08:02 1,361,296 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zpy.zip.dll
+ 2008-04-03 02:08:02 71,056 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zui.zip.dll
+ 2008-04-03 02:09:10 30,184 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\rpc_server\rpc_server.dll
+ 2008-04-03 02:09:12 30,216 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\vsmon_plugin\vsmon_plugin.dll
+ 2008-02-27 09:10:26 714,208 ----a-w C:\WINDOWS\system32\ZoneLabs\qrbase.dll
+ 2008-02-27 09:10:28 792,032 ----a-w C:\WINDOWS\system32\ZoneLabs\qrsrecl.dll
+ 2008-04-03 02:07:38 173,544 ----a-w C:\WINDOWS\system32\ZoneLabs\scheduler.dll
+ 2008-01-21 14:34:36 7,603,688 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
+ 2008-02-27 09:10:32 1,504,736 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.dll
+ 2008-02-27 09:10:44 51,176 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.sys
+ 2008-04-03 02:07:38 456,168 ----a-w C:\WINDOWS\system32\ZoneLabs\ssleay32.dll
+ 2008-04-03 02:09:12 214,528 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
+ 2008-04-03 02:09:14 3,266,040 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\imslsp\imslsp.dll
+ 2006-09-05 02:59:14 503,875 ----a-w C:\WINDOWS\system32\ZoneLabs\upd_core.dll
+ 2007-10-11 22:50:32 832,984 ----a-w C:\WINDOWS\system32\ZoneLabs\updating.dll
+ 2008-04-03 02:07:54 144,936 ----a-w C:\WINDOWS\system32\ZoneLabs\updclient.exe
+ 2007-01-11 23:31:06 286,787 ----a-w C:\WINDOWS\system32\ZoneLabs\updtrsdk.dll
+ 2008-04-03 02:07:40 108,008 ----a-w C:\WINDOWS\system32\ZoneLabs\vsavpro.dll
+ 2008-04-03 02:07:40 83,432 ----a-w C:\WINDOWS\system32\ZoneLabs\vsdb.dll
+ 2008-04-03 02:07:54 75,304 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmon.exe
+ 2008-04-03 02:07:40 2,029,032 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmondll.dll
+ 2008-04-03 02:07:42 1,361,384 ----a-w C:\WINDOWS\system32\ZoneLabs\vsruledb.dll
+ 2008-04-03 02:07:42 239,080 ----a-w C:\WINDOWS\system32\ZoneLabs\vsvault.dll
+ 2008-01-21 14:34:36 7,603,688 ----a-w C:\WINDOWS\system32\ZoneLabs\zlasdbup.dat
+ 2008-04-03 02:07:44 177,640 ----a-w C:\WINDOWS\system32\ZoneLabs\zlparser.dll
+ 2008-04-03 02:07:44 79,344 ----a-w C:\WINDOWS\system32\ZoneLabs\zlquarantine.dll
+ 2008-04-03 02:07:46 382,440 ----a-w C:\WINDOWS\system32\ZoneLabs\zlsre.dll
+ 2008-04-03 02:07:46 120,296 ----a-w C:\WINDOWS\system32\ZoneLabs\zlupdate.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" [2008-05-13 18:34 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CARPService"="carpserv.exe" [2008-04-13 21:24 4608 C:\WINDOWS\system32\carpserv.exe]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2008-04-12 18:39 114688]
"HKSERV.EXE"="C:\Program Files\Sony\HotKey Utility\HKserv.exe" [2008-04-12 18:39 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-04-12 18:39 77824]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 12:29 40960]
"ZTgServerSwitch"="c:\program files\support.com\client\bin\tgcmd.exe" [2008-04-12 18:39 1409024]
"ATIModeChange"="Ati2mdxx.exe" [2008-04-13 21:24 28672 C:\WINDOWS\system32\ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2008-04-12 18:39 323584]
"VAIO Recovery"="C:\Windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 00:08 28672]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 21:07 919016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
*Newly Created Service* - CATCHME
*Newly Created Service* - SRESCAN
*Newly Created Service* - VSMON
.
Contents of the 'Scheduled Tasks' folder
"2007-04-16 06:39:46 C:\WINDOWS\Tasks\Registration reminder 1.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2007-04-16 06:39:47 C:\WINDOWS\Tasks\Registration reminder 2.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2007-04-16 06:39:47 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2007-12-04 19:16:04 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-14 08:28:32
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-14 8:30:12
ComboFix-quarantined-files.txt 2008-05-14 13:30:08
ComboFix2.txt 2008-05-13 22:58:05
ComboFix3.txt 2008-05-12 17:49:14
ComboFix4.txt 2008-05-09 21:15:57
C:\DeQuarantine.txt
Pre-Run: 8,515,108,864 bytes free
Post-Run: 8,518,529,024 bytes free
195
At the end of the process, after the log appeared, Notepad gave me a dialog box with "Cannot find the \DeQuarantine.txt file. Do you want to create a new file?" What should I do with that?
I have left it at that point.
I was going to run ComboFix in safe mode again to see what the differance would be, but maybe that is not necasary.
Still no WinReanimator icon at this point.
I ran ComboFix in regular mode, here is the log:
ComboFix 08-05-07.2 - Robin 2008-05-14 8:26:29.10 - NTFSx86
Running from: C:\Combo-Fix.exe
Command switches used :: E:\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\Drivers\beep.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Drivers\beep.sys
.
((((((((((((((((((((((((( Files Created from 2008-04-14 to 2008-05-14 )))))))))))))))))))))))))))))))
.
2008-05-14 08:25 . 2008-05-14 08:26 <DIR> d-------- C:\WINDOWS\Drivers
2008-05-13 18:34 . 2008-05-13 18:34 <DIR> d-------- C:\Program Files\ZoneAlarmSB
2008-05-13 18:31 . 2008-05-13 18:31 <DIR> d-------- C:\Program Files\Zone Labs
2008-05-13 18:31 . 2008-05-13 18:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-05-13 18:29 . 2008-05-14 08:24 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-05-12 13:52 . 2008-05-12 13:52 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-12 13:52 . 2008-05-12 13:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-12 12:52 . 2008-05-13 02:52 206 --a------ C:\Documents and Settings\Robin\delself.bat
2008-05-08 18:07 . 2003-08-01 15:17 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\MSN6
2008-05-08 18:07 . 2003-08-01 16:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-05-08 18:07 . 2008-05-08 18:07 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-08 18:07 . 2008-05-13 18:00 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-05-08 16:22 . 2008-05-09 16:05 1,850,852 --a------ C:\Combo-Fix.exe
2008-05-08 11:12 . 2008-05-08 11:12 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-08 11:12 . 2008-05-08 11:12 <DIR> d-------- C:\Documents and Settings\Robin\Application Data\Malwarebytes
2008-05-08 11:12 . 2008-05-08 11:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-08 11:12 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-08 11:12 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-04-29 02:29 . 2008-04-29 02:29 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-04-29 01:48 . 2008-04-29 01:48 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-29 00:59 . 2008-05-09 00:39 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-29 00:26 . 2008-04-29 00:26 0 --a------ C:\winamp.ini
2008-04-29 00:22 . 2008-05-09 00:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-29 06:03 --------- d-----w C:\Documents and Settings\Robin\Application Data\Symantec
2008-04-29 05:51 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-29 05:49 --------- d-----w C:\Program Files\Symantec
2008-04-29 05:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-14 02:24 4,608 ----a-w C:\WINDOWS\system32\carpserv.exe
2008-04-14 02:24 28,672 ----a-w C:\WINDOWS\system32\ati2mdxx.exe
2008-04-14 00:21 --------- d-----w C:\Program Files\QuickTime
2008-04-14 00:21 --------- d-----w C:\Program Files\Apoint
2008-04-03 02:07 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-04-03 02:07 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
.
Files Infected - Win32.Agent.zb
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\Program Files\QuickTime\qttask.exe
c:\program files\support.com\client\bin\tgcmd.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
.
((((((((((((((((((((((((((((( snapshot@2008-05-09_16.15.32.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-09 21:12:42 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-13 23:36:36 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2005-05-24 17:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-04-03 02:07:36 796,048 ----a-w C:\WINDOWS\system32\libeay32_0.9.6l.dll
+ 2004-04-27 10:40:52 11,264 ----a-w C:\WINDOWS\system32\SpOrder.dll
+ 2008-04-03 02:07:40 83,432 ----a-w C:\WINDOWS\system32\vsdata.dll
+ 2008-04-03 02:08:00 394,952 ----a-w C:\WINDOWS\system32\vsdatant.sys
+ 2008-04-03 02:07:40 157,160 ----a-w C:\WINDOWS\system32\vsinit.dll
+ 2008-04-03 02:07:40 103,912 ----a-w C:\WINDOWS\system32\vsmonapi.dll
+ 2008-04-03 02:07:40 275,944 ----a-w C:\WINDOWS\system32\vspubapi.dll
+ 2008-04-03 02:07:42 71,144 ----a-w C:\WINDOWS\system32\vsregexp.dll
+ 2008-04-03 02:07:42 472,552 ----a-w C:\WINDOWS\system32\vsutil.dll
+ 2008-04-03 02:07:42 46,568 ----a-w C:\WINDOWS\system32\vswmi.dll
+ 2008-04-03 02:07:42 99,816 ----a-w C:\WINDOWS\system32\vsxml.dll
+ 2008-04-03 02:07:44 83,432 ----a-w C:\WINDOWS\system32\zlcomm.dll
+ 2008-04-03 02:07:44 71,144 ----a-w C:\WINDOWS\system32\zlcommdb.dll
+ 2008-05-13 23:34:49 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
+ 2008-04-03 02:07:32 370,208 ----a-w C:\WINDOWS\system32\ZoneLabs\av.dll
+ 2007-05-31 06:03:30 65,248 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\aphish.dat
+ 2006-06-30 20:47:36 21,568 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\avcmhk4.dll
+ 2007-05-31 06:03:30 1,628 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\pdmkl.dat
+ 2007-05-31 06:03:16 77,824 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHComm.dll
+ 2007-05-31 06:03:16 110,592 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHrule.dll
+ 2007-05-31 06:03:16 331,776 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHUM.dll
+ 2007-05-31 06:03:16 38,400 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\FSSync.dll
+ 2006-09-20 05:12:14 208,960 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\inv.dll
+ 2007-12-03 20:53:58 282,624 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\kave.dll
+ 2007-07-19 21:10:32 186,128 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\klif_32.sys
+ 2006-12-20 00:13:52 1,093,632 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\libeay32.dll
+ 2007-05-31 06:03:20 548,864 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcp80.dll
+ 2007-05-31 06:03:20 626,688 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcr80.dll
+ 2007-05-31 06:03:18 184,320 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\prloader.dll
+ 2007-05-31 06:03:22 90,112 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\prremote.dll
+ 2007-12-03 20:53:58 139,264 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
+ 2006-12-20 00:13:52 200,704 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ssleay32.dll
+ 2008-04-03 02:07:32 99,816 ----a-w C:\WINDOWS\system32\ZoneLabs\camupd.dll
+ 2004-01-30 18:35:08 813,568 ----a-w C:\WINDOWS\system32\ZoneLabs\dbghelp.dll
+ 2008-04-03 02:07:34 128,480 ----a-w C:\WINDOWS\system32\ZoneLabs\fbl.dll
+ 2008-04-03 02:07:34 38,376 ----a-w C:\WINDOWS\system32\ZoneLabs\featuremap.dll
+ 2008-04-03 02:07:34 321,016 ----a-w C:\WINDOWS\system32\ZoneLabs\imsecure.dll
+ 2008-04-03 02:08:02 288,144 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\ConfigWizard.zip.dll
+ 2008-04-03 02:08:02 152,976 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\licenseui.zip.dll
+ 2008-04-03 02:08:02 26,000 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zlsvc.zip.dll
+ 2008-04-03 02:08:02 1,361,296 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zpy.zip.dll
+ 2008-04-03 02:08:02 71,056 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zui.zip.dll
+ 2008-04-03 02:09:10 30,184 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\rpc_server\rpc_server.dll
+ 2008-04-03 02:09:12 30,216 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\vsmon_plugin\vsmon_plugin.dll
+ 2008-02-27 09:10:26 714,208 ----a-w C:\WINDOWS\system32\ZoneLabs\qrbase.dll
+ 2008-02-27 09:10:28 792,032 ----a-w C:\WINDOWS\system32\ZoneLabs\qrsrecl.dll
+ 2008-04-03 02:07:38 173,544 ----a-w C:\WINDOWS\system32\ZoneLabs\scheduler.dll
+ 2008-01-21 14:34:36 7,603,688 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
+ 2008-02-27 09:10:32 1,504,736 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.dll
+ 2008-02-27 09:10:44 51,176 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.sys
+ 2008-04-03 02:07:38 456,168 ----a-w C:\WINDOWS\system32\ZoneLabs\ssleay32.dll
+ 2008-04-03 02:09:12 214,528 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
+ 2008-04-03 02:09:14 3,266,040 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\imslsp\imslsp.dll
+ 2006-09-05 02:59:14 503,875 ----a-w C:\WINDOWS\system32\ZoneLabs\upd_core.dll
+ 2007-10-11 22:50:32 832,984 ----a-w C:\WINDOWS\system32\ZoneLabs\updating.dll
+ 2008-04-03 02:07:54 144,936 ----a-w C:\WINDOWS\system32\ZoneLabs\updclient.exe
+ 2007-01-11 23:31:06 286,787 ----a-w C:\WINDOWS\system32\ZoneLabs\updtrsdk.dll
+ 2008-04-03 02:07:40 108,008 ----a-w C:\WINDOWS\system32\ZoneLabs\vsavpro.dll
+ 2008-04-03 02:07:40 83,432 ----a-w C:\WINDOWS\system32\ZoneLabs\vsdb.dll
+ 2008-04-03 02:07:54 75,304 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmon.exe
+ 2008-04-03 02:07:40 2,029,032 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmondll.dll
+ 2008-04-03 02:07:42 1,361,384 ----a-w C:\WINDOWS\system32\ZoneLabs\vsruledb.dll
+ 2008-04-03 02:07:42 239,080 ----a-w C:\WINDOWS\system32\ZoneLabs\vsvault.dll
+ 2008-01-21 14:34:36 7,603,688 ----a-w C:\WINDOWS\system32\ZoneLabs\zlasdbup.dat
+ 2008-04-03 02:07:44 177,640 ----a-w C:\WINDOWS\system32\ZoneLabs\zlparser.dll
+ 2008-04-03 02:07:44 79,344 ----a-w C:\WINDOWS\system32\ZoneLabs\zlquarantine.dll
+ 2008-04-03 02:07:46 382,440 ----a-w C:\WINDOWS\system32\ZoneLabs\zlsre.dll
+ 2008-04-03 02:07:46 120,296 ----a-w C:\WINDOWS\system32\ZoneLabs\zlupdate.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" [2008-05-13 18:34 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CARPService"="carpserv.exe" [2008-04-13 21:24 4608 C:\WINDOWS\system32\carpserv.exe]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2008-04-12 18:39 114688]
"HKSERV.EXE"="C:\Program Files\Sony\HotKey Utility\HKserv.exe" [2008-04-12 18:39 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-04-12 18:39 77824]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 12:29 40960]
"ZTgServerSwitch"="c:\program files\support.com\client\bin\tgcmd.exe" [2008-04-12 18:39 1409024]
"ATIModeChange"="Ati2mdxx.exe" [2008-04-13 21:24 28672 C:\WINDOWS\system32\ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2008-04-12 18:39 323584]
"VAIO Recovery"="C:\Windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 00:08 28672]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 21:07 919016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
*Newly Created Service* - CATCHME
*Newly Created Service* - SRESCAN
*Newly Created Service* - VSMON
.
Contents of the 'Scheduled Tasks' folder
"2007-04-16 06:39:46 C:\WINDOWS\Tasks\Registration reminder 1.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2007-04-16 06:39:47 C:\WINDOWS\Tasks\Registration reminder 2.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2007-04-16 06:39:47 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2007-12-04 19:16:04 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-14 08:28:32
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-14 8:30:12
ComboFix-quarantined-files.txt 2008-05-14 13:30:08
ComboFix2.txt 2008-05-13 22:58:05
ComboFix3.txt 2008-05-12 17:49:14
ComboFix4.txt 2008-05-09 21:15:57
C:\DeQuarantine.txt
Pre-Run: 8,515,108,864 bytes free
Post-Run: 8,518,529,024 bytes free
195
At the end of the process, after the log appeared, Notepad gave me a dialog box with "Cannot find the \DeQuarantine.txt file. Do you want to create a new file?" What should I do with that?
I have left it at that point.
I was going to run ComboFix in safe mode again to see what the differance would be, but maybe that is not necasary.
Still no WinReanimator icon at this point.