As a shot in the dark, I just ran Combofix. It said it found a few files and "Bootkit - TDL4" and disinfected it. Here are the files that it found from ComboFix:
2011-04-18 18:49:25 . 2011-04-18 18:49:25 814 ----a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-PreSonus 1394 Audio Driver V2.27.0 (EASERA GATEWAY) Setup.reg.dat
2011-04-18 18:47:11 . 2011-04-18 18:47:11 8,801 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2011-04-18 18:28:41 . 2011-04-18 18:41:22 121 ----a-w- C:\Qoobox\Quarantine\catchme.log
2010-12-22 21:26:32 . 2010-12-22 21:26:32 1 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\idmf.dat.vir
2010-12-22 21:26:32 . 2010-12-22 21:26:32 1 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\fdscd.dat.vir
2010-11-10 22:44:39 . 2011-03-04 19:45:33 225,836 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\lkdsd.dat.vir
2010-05-19 21:32:45 . 2010-11-17 23:29:09 45,056 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\loml.gif.vir
2009-06-29 16:52:56 . 2009-06-29 16:52:56 2,443,571 ----a-w- C:\Qoobox\Quarantine\C\PROGRA~1\RENKUS~1\RHAON\COT144.exe.vir
2007-02-22 17:42:45 . 2009-11-14 19:28:09 120 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\winsusrx.dll.vir
2007-02-22 17:42:45 . 2010-11-17 22:45:14 264 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\winsusrm.dll.vir
So, it didn't fix the problem of opening taskmanager or regedit though. So I tried the fixes mentioned here:
http://www.dougknox.com/security/scripts_desc/regtools.htm
http://windowsxp.mvps.org/Taskmanager_error.htm
And it was fixed momentarily untill I logged off or rebooted, then I was back to no regedit or taskmanager.
So, I just ran the DDS tool and GMER and am posting my logs here.
Also, as a test, I ran ComboFix on a machine that DIDN'T have the regedit/taskmanager problem and it too still found some files and Bootkit-TDL4.
So here are my logs. Any help would be appreciated!! Thank you!!!!!!
Jonas
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by EaseUser at 12:21:18.56 on Mon 04/18/2011
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.654 [GMT -7:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\RH_PreSonus\1394AudioDriver_EASERA_GATEWAY\EASERA_Gateway.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\EaseUser\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.renkus-heinz.com/
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {2C5EB892-1B87-449E-A13F-7BC1112C99EB} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [RoxioEngineUtility] "c:\program files\common files\roxio shared\system\EngUtil.exe"
mRun: [EASERA 1.1] c:\program files\sda\easera 1.0\easera100\InitCrypKey.exe
mRun: [vptray] c:\progra~1\symant~1\symant~1\vptray.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\easera~1.lnk - c:\program files\rh_presonus\1394audiodriver_easera_gateway\EASERA_Gateway.exe
uPolicies-system: DisableTaskMgr = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1172101521109
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
mASetup: {E7F780A5-FC7C-45C5-882E-256832665E0A} - rundll32 rxten.dll,laspi
.
============= SERVICES / DRIVERS ===============
.
R2 NAVAPEL;NAVAPEL;c:\program files\symantec_client_security\symantec antivirus\Navapel.sys [2002-6-19 29184]
R2 Norton AntiVirus Server;Symantec AntiVirus Client;c:\program files\symantec_client_security\symantec antivirus\Rtvscan.exe [2002-7-30 573440]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-1-26 50704]
R3 NAVAP;NAVAP;c:\program files\symantec_client_security\symantec antivirus\Navap.sys [2002-6-19 218112]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20071114.020\NAVENG.sys [2007-11-15 81232]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20071114.020\NAVEX15.sys [2007-11-15 865904]
S3 SDA_1394;SDA_1394;c:\windows\system32\drivers\SDA_1394.sys [2007-2-22 113664]
S3 SDA_avs;SDA_avs;c:\windows\system32\drivers\SDA_avs.sys [2007-2-22 28672]
.
=============== Created Last 30 ================
.
2011-04-18 18:59:14 -------- d--h--w- c:\windows\system32\GroupPolicy
2011-04-18 18:31:52 984064 ----a-w- c:\windows\system32\OLD2.tmp
2011-04-18 18:28:50 98816 ----a-w- c:\windows\sed.exe
2011-04-18 18:28:50 89088 ----a-w- c:\windows\MBR.exe
2011-04-18 18:28:50 256512 ----a-w- c:\windows\PEV.exe
2011-04-18 18:28:50 161792 ----a-w- c:\windows\SWREG.exe
.
==================== Find3M ====================
.
2011-01-26 00:47:10 125760 ----a-w- c:\windows\system32\W32N55.dll
.
============= FINISH: 12:21:55.01 ===============
Attached File(s)
-
Attach.txt (7.05K)
Number of downloads: 2 -
ark.txt (2.5K)
Number of downloads: 4

Help
This topic is locked


Back to top











