DDS Log:
********
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Owner at 9:24:56.01 on Fri 04/29/2011
Internet Explorer: 6.0.2800.1106 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.504.134 [GMT -5:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hasplms.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\EPC\Toolbar\EPSIBar.exe
C:\WINDOWS\System32\GRVSA.exe
C:\ALLDATAW\Ace.exe
C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe
C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\agent.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\My Documents\Downloads\dds.com
.
============== Pseudo HJT Report ===============
.
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {243b17de-77c7-46bf-b94b-0b5f309a0e64} - c:\program files\microsoft money\system\mnyside.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\System32\browseui.dll
uRun: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [KBD] c:\hp\kbd\KBD.EXE
mRun: [StorageGuard] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
mRun: [AlcxMonitor] ALCXMNTR.EXE
mRun: [PS2] c:\windows\system32\ps2.exe
mRun: [wcmdmgr] c:\windows\wt\updater\wcmdmgrl.exe -launch
mRun: [BrStsWnd] c:\program files\brownie\BrstsWnd.exe Autorun
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\epsito~1.lnk - c:\epc\toolbar\EPSIBar.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {DD6687B5-CB43-4211-BFC9-2942CCBDCB3E} - c:\program files\microsoft money\system\mnyside.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} - file://c:\program files\intercap\activecgm\activex\Acgm.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: igfxcui - igfxsrvc.dll
Notify: OPXPGina - c:\program files\softex\omnipass\opxpgina.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\rcz40zwh.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50370
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
.
============= SERVICES / DRIVERS ===============
.
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [2010-8-5 1714176]
S2 mrtRate;mrtRate; [x]
.
=============== Created Last 30 ================
.
2011-04-28 21:16:09 161296 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-04-28 21:16:09 -------- d-----w- c:\documents and settings\owner\log
2011-04-28 19:08:34 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-28 19:08:30 19288 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-28 18:57:49 -------- d-----w- c:\docume~1\owner\locals~1\applic~1\Sunbelt Software
2011-04-11 16:09:52 781272 ----a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-04-11 16:09:51 1874904 ----a-w- c:\program files\mozilla firefox\mozjs.dll
2011-04-11 16:09:50 728024 ----a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-04-11 16:09:50 15832 ----a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-04-11 16:09:50 142296 ----a-w- c:\program files\mozilla firefox\libEGL.dll
2011-04-11 16:09:49 1893336 ----a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-04-11 16:09:49 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-11 16:09:48 1975768 ----a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
.
==================== Find3M ====================
.
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600 Disk: ST3120025A rev.4.06 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x822424F0]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x822487d0]; MOV EAX, [0x8224884c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804ED850] -> \Device\Harddisk0\DR0[0x82250B48]
3 CLASSPNP[0xF84C0022] -> nt!IofCallDriver[0x804ED850] -> \Device\00000055[0x822AEF18]
5 ACPI[0xF841812D] -> nt!IofCallDriver[0x804ED850] -> [0x82251B58]
\Driver\atapi[0x82258880] -> IRP_MJ_CREATE -> 0x822424F0
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR DI, DI; MOV SI, 0x200; MOV SS, DI; MOV SP, 0x7a00; MOV BX, 0x7a0; MOV CX, SI; MOV DS, BX; MOV ES, BX; CLD ; REP MOVSB ; JMP FAR 0x7a0:0x52; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8224233B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 9:26:30.65 ===============
Gmer Log:
*********
GMER 1.0.15.15572 -
http://www.gmer.net
Rootkit scan 2011-04-29 10:40:45
Windows 5.1.2600 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdePort0 ST3120025A rev.4.06
Running: v2t8l4dc.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\uwtiquoc.sys
---- System - GMER 1.0.15 ----
SSDT \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation) ZwCreateKey [0x804D4571]
SSDT \WINDOWS\system32\ntoskrnl.exe[unknown section] [804D4571] ZwCreateKey [0x804D4571]
SSDT \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation) ZwOpenKey [0x804D4576]
SSDT \WINDOWS\system32\ntoskrnl.exe[unknown section] [804D4576] ZwOpenKey [0x804D4576]
INT 0x03 \WINDOWS\system32\ntoskrnl.exe[unknown section] 804D457B
INT 0x06 \??\C:\WINDOWS\System32\drivers\Haspnt.sys (HASP Kernel Device Driver for Windows NT/Aladdin Knowledge Systems) EF6E416D
INT 0x0E \??\C:\WINDOWS\System32\drivers\Haspnt.sys (HASP Kernel Device Driver for Windows NT/Aladdin Knowledge Systems) EF6E3FC2
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!KeInitializeInterrupt + B67 804DA23C 1 Byte [06]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 1B0 8050262C 3 Bytes [71, 45, 4D] {JNO 0x47; DEC EBP}
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 2E8 80502764 3 Bytes [76, 45, 4D] {JBE 0x47; DEC EBP}
? wtfil.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\drivers\aksfridge.sys section is writeable [0xB586E000, 0x48011, 0xE0000020]
.init C:\WINDOWS\system32\drivers\aksfridge.sys entry point in ".init" section [0xB58C3224]
.init C:\WINDOWS\system32\drivers\aksfridge.sys unknown last code section [0xB58C3000, 0x4000, 0xE20000E0]
.text C:\WINDOWS\system32\drivers\hardlock.sys section is writeable [0xB57DD400, 0x6E1B2, 0xE8000020]
.protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".p" section [0xB5867220] C:\WINDOWS\system32\drivers\hardlock.sys entry point in ".protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".p" section [0xB5867220]
.protectÿÿÿÿhardlockunknown last code section [0xB5867000, 0x50EA, 0xE0000020] C:\WINDOWS\system32\drivers\hardlock.sys unknown last code section [0xB5867000, 0x50EA, 0xE0000020]
? C:\DOCUME~1\Owner\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[172] ntdll.dll!NtProtectVirtualMemory 77F75F36 5 Bytes JMP 0099000A
.text C:\WINDOWS\Explorer.EXE[172] ntdll.dll!NtWriteVirtualMemory 77F76768 5 Bytes JMP 009A000A
.text C:\WINDOWS\Explorer.EXE[172] ntdll.dll!KiUserExceptionDispatcher 77FB4DAF 5 Bytes JMP 0098000C
.text C:\WINDOWS\System32\svchost.exe[888] ntdll.dll!NtProtectVirtualMemory 77F75F36 5 Bytes JMP 007F000A
.text C:\WINDOWS\System32\svchost.exe[888] ntdll.dll!NtWriteVirtualMemory 77F76768 5 Bytes JMP 0080000A
.text C:\WINDOWS\System32\svchost.exe[888] ntdll.dll!KiUserExceptionDispatcher 77FB4DAF 5 Bytes JMP 007E000C
.text C:\WINDOWS\System32\svchost.exe[888] ole32.dll!CoCreateInstance 771C2087 5 Bytes JMP 0090000B
.text C:\WINDOWS\System32\svchost.exe[888] USER32.dll!GetCursorPos 77D441C0 5 Bytes JMP 0331000B
.text C:\WINDOWS\System32\svchost.exe[888] USER32.dll!WindowFromPoint 77D4466B 5 Bytes JMP 0332000A
.text C:\WINDOWS\System32\svchost.exe[888] USER32.dll!GetForegroundWindow 77D4686F 5 Bytes JMP 0333000A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2628] USER32.dll!GetWindowInfo 77D4A937 5 Bytes JMP 104C7C37 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2628] USER32.dll!TrackPopupMenu 77D8DFE6 5 Bytes JMP 104C823A C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2656] ntdll.dll!NtProtectVirtualMemory 77F75F36 5 Bytes JMP 01C9000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2656] ntdll.dll!NtWriteVirtualMemory 77F76768 5 Bytes JMP 01CA000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2656] ntdll.dll!KiUserExceptionDispatcher 77FB4DAF 5 Bytes JMP 01C8000C
.text C:\Program Files\Mozilla Firefox\firefox.exe[3396] ntdll.dll!LdrLoadDll 77F55669 5 Bytes JMP 00401410 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T1L0-17 8224233B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 8224233B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-3 8224233B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 8224233B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-f 8224233B
Device \Driver\Disk \Device\Harddisk0\DR0 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.)
Device \Driver\Disk \Device\Harddisk1\DR3 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.)
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+4 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@InstallService 1
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 TDL4@MBR code has been found <-- ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8355T2II\CA2A7F1S.php 0 bytes
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8355T2II\spc.ceickgjggfadafkengfhafbe.carousel.telemetryverification[1].xml 2367 bytes
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8355T2II\tpl_player[1] 0 bytes
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8355T2II\CAP33XVX.y%3D12 28 bytes
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8355T2II\january-jones-fell[1].jpeg 2817 bytes
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8355T2II\january-jones-fell[2].jpeg 36504 bytes
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8355T2II\glamadapt_jsrv[5] 2496 bytes
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8355T2II\viewChannelModule[1].act 14019 bytes
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\MLNT2SHM\CA2C1J76.html 11 bytes
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UZN8KCDN\newgc[1].css 0 bytes
---- EOF - GMER 1.0.15 ----