.
DDS (Ver_11-03-05.01) - NTFSx86
Run by BMiller at 9:19:48.08 on Fri 04/08/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.280 [GMT -4:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Altiris\Aclient\AClient.exe
C:\Program Files\Altiris\Altiris Agent\aexnsagent.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\Program Files\Canon\DIAS\CnxDIAS.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\hasplms.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\lotus\notes\nsd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\lotus\notes\ntmulti.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\StacSV.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\svchost.exe -k HPService
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Altiris\Aclient\AClntUsr.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Altiris\Altiris Agent\AeXAgentUIHost.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellTPad\Apntex.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\lotus\notes\NLNOTES.EXE
C:\lotus\notes\framework\rcp\eclipse\plugins\com.ibm.rcp.base_6.2.1.20090925-1604\win32\x86\notes2.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\lotus\notes\ntaskldr.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\BMiller.INT\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://secure.constructware.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Pistolstar Web SSO: {f01a34b2-0067-431c-a5e1-eff58d85c9be} - c:\program files\pistolstar\password power client\IE_SSO_Toolbar.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Pistolstar Web SSO: {f01a34b2-0067-431c-a5e1-eff58d85c9be} - c:\program files\pistolstar\password power client\IE_SSO_Toolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [AClntUsr] c:\program files\altiris\aclient\AClntUsr.EXE
mRun: [Logon Script Launcher] c:\vpnraslogonhook.vbs
mRun: [Client Access Service] "c:\program files\ibm\client access\cwbsvstr.exe"
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
mRun: [AeXAgentLogon] c:\program files\altiris\altiris agent\AeXAgentActivate.exe /logon
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
mRun: [Pistolstar_SSO] "c:\program files\pistolstar\password power client\APOSSO.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{871df2be-41d2-4334-ac33-839af16fc8fe}\Icon3E5562ED7.ico
uPolicies-explorer: ForceStartMenuLogOff = 1 (0x1)
uPolicies-explorer: NoWelcomeScreen = 1 (0x1)
mPolicies-explorer: NoMSAppLogo5ChannelNotify = 1 (0x1)
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {01892B12-4ABE-47E8-B7C1-4692F0B74024} - hxxps://drawing.constructware.com/IGC/BravaClientX.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=67633
DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} - hxxp://intranet.clarkus.com/qp2.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} - hxxps://secure.constructware.com/FileTransfer/SoftwareArtisans/saxfile.cab
DPF: {36F17E17-AC00-42BC-A6D9-294AD4E7DCD6} - hxxp://ccgbthaltns.int.clarkus.com/Altiris/NS/NSCap/Bin/Win32/x86/AeXClientBootstrap.cab
DPF: {5BDBA960-6534-11D3-97C7-00500422B550} - hxxps://clarkmail.clarkus.com/download/dolcontrol.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1201882458203
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {983A9C21-8207-4B58-BBB8-0EBC3D7C5505} - hxxps://clarkmail.clarkus.com/dwa8W.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D79BD4AB-C8E1-48C7-9A86-DF163C340383} - hxxp://ccgbthdom2.clarkus.com/sametime/stmeetingroomclient/STJNILoader.cab
DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} - hxxps://clarkmail.clarkus.com/dwa7W.cab
DPF: {F8C41CBF-721F-4B99-9FC8-2F8077C4AD39} - hxxps://drawing.constructware.com/IGC/BravaClientX.cab
Notify: igfxcui - igfxdev.dll
Notify: itlnfw32 - itlnfw32.dll
Notify: itlntfy - itlnfw32.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
Notify: PCANotify - PCANotify.dll
AppInit_DLLs: AMINIT32.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-4-7 64512]
R1 awlegacy;awlegacy;c:\windows\system32\drivers\AWLEGACY.sys [2007-3-30 17848]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-12-19 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-12-19 54968]
R2 awhost32;Symantec pcAnywhere Host Service;c:\program files\symantec\pcanywhere\awhost32.exe [2009-2-9 136568]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-3-24 192160]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-3-24 169632]
R2 hasplms;Sentinel HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-4-1 1753048]
R2 Lotus Notes Diagnostics;Lotus Notes Diagnostics;c:\lotus\notes\nsd.exe -svcinvoke -ini "c:\lotus\notes\notes.ini" --> c:\lotus\notes\nsd.exe -svcinvoke -ini c:\lotus\notes\notes.ini [?]
R2 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-6-15 115952]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-6-15 1805552]
R2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [2007-11-6 6016]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-11-12 102448]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-4-1 15232]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20110407.002\naveng.sys [2011-4-7 86136]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20110407.002\navex15.sys [2011-4-7 1393144]
S0 cerc6;cerc6; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-4-29 136176]
S3 AltirisAgentProvider;AltirisAgentProvider;c:\program files\altiris\altiris agent\agents\wmiprovideragent\AltirisAgentProvider.exe [2009-8-25 614400]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\androidusb.sys --> c:\windows\system32\drivers\ANDROIDUSB.sys [?]
S3 pneteth;PdaNet Broadband;c:\windows\system32\drivers\pneteth.sys [2010-8-18 13184]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]
S4 AW_HOST;AW_HOST;c:\windows\system32\drivers\AW_HOST5.sys [2007-3-30 18232]
.
=============== Created Last 30 ================
.
2011-04-08 12:08:44 -------- d-----w- c:\docume~1\bmiller.int\applic~1\smkits
2011-04-07 16:51:13 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-04-07 15:57:08 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-04-07 15:56:55 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-04-07 15:46:25 -------- d-----w- c:\docume~1\bmiller.int\locals~1\applic~1\Sunbelt Software
2011-04-07 15:44:32 -------- dc-h--w- c:\docume~1\alluse~1\applic~1\{6A395471-4AA3-4072-AE1B-9B69A97AD164}
2011-04-07 15:43:49 -------- d-----w- c:\program files\Lavasoft
2011-04-06 18:40:46 -------- d-----w- c:\documents and settings\bmiller.int\SametimeTranscripts
2011-04-05 11:33:35 -------- d-sh--w- c:\documents and settings\bmiller.int\IECompatCache
2011-03-31 11:20:23 0 ----a-w- c:\windows\Ayehoxebux.bin
2011-03-31 11:20:22 -------- d-----w- c:\docume~1\bmiller.int\locals~1\applic~1\{18207F01-7DEB-4E05-9E6D-0E239191FB16}
2011-03-30 20:56:17 2768 ----a-w- c:\windows\ojovumeg.dll
2011-03-30 18:54:19 2768 ----a-w- c:\windows\arumarigafey.dll
2011-03-30 17:30:35 -------- d-----w- c:\docume~1\bmiller.int\locals~1\applic~1\Apple Computer
2011-03-30 14:18:25 2768 ----a-w- c:\windows\ogadageq.dll
2011-03-30 14:09:10 2768 ----a-w- c:\windows\ucicesofihut.dll
2011-03-30 13:51:12 2768 ----a-w- c:\windows\igulivih.dll
2011-03-30 13:14:20 -------- d-----w- c:\docume~1\bmiller.int\applic~1\Malwarebytes
2011-03-30 12:04:08 2768 ----a-w- c:\windows\atokoziy.dll
2011-03-29 21:27:55 2768 ----a-w- c:\windows\ijokuqis.dll
2011-03-29 19:37:34 34816 ----a-w- c:\windows\system32\itlnfw32.dll
2011-03-29 19:25:55 2768 ----a-w- c:\windows\ilodokez.dll
2011-03-29 17:23:55 2768 ----a-w- c:\windows\izohibew.dll
2011-03-29 15:22:05 2766 ----a-w- c:\windows\agevanoqiq.dll
2011-03-29 15:21:23 108032 --sha-r- c:\windows\system32\msdatsrcb.dll
2011-03-22 14:55:04 -------- d-----w- c:\docume~1\bmiller.int\locals~1\applic~1\Autodesk
2011-03-17 19:04:21 -------- d-----w- c:\windows\system32\CCM
2011-03-17 19:04:21 -------- d-----w- c:\windows\ms
2011-03-17 19:03:27 -------- d-----w- c:\program files\Windows Imaging
2011-03-17 19:03:11 -------- dc-h--w- c:\windows\$UninstallRDC$
2011-03-17 19:00:16 -------- d-----w- c:\windows\system32\ccmsetup
2011-03-17 11:28:46 -------- d-sh--w- c:\documents and settings\bmiller.int\PrivacIE
2011-03-17 11:26:43 -------- d-----w- c:\docume~1\bmiller.int\locals~1\applic~1\Adobe
2011-03-17 11:26:24 -------- d-----w- c:\docume~1\bmiller.int\locals~1\applic~1\Symantec
2011-03-17 11:25:04 45056 ----a-r- c:\docume~1\bmiller.int\applic~1\microsoft\installer\{42929f0f-ce14-47af-9fc7-ff297a603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe
.
==================== Find3M ====================
.
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST9160314AS rev.D005DEM1 -> Harddisk0\DR0 -> \Device\Ide\IdePort1 P1T0L0-e
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x86C6C439]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x86c727d0]; MOV EAX, [0x86c7284c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x86C82AB8]
3 CLASSPNP[0xF75AEFD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x86C389A0]
\Driver\atapi[0x86DD4CC8] -> IRP_MJ_CREATE -> 0x86C6C439
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Ide\IdeDeviceP1T0L0-e -> \??\IDE#DiskST9160314AS_____________________________D005DEM1#5&266ff5a6&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x86C6C27F
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 9:23:43.93 ===============
Attached File(s)
-
Attach.txt (16.57K)
Number of downloads: 1 -
Ark.txt (43.85K)
Number of downloads: 0

Help
This topic is locked

Back to top












