Risk name: Tidserv activity 2
Attacking computer: litOgraphy-type.com (188.95.52.161, 443
Destination Address: KING-E6AEE95FF1 (192.168.2.101, 1040
Source Address: 188.95.52.161
Traffic Description: TCP, https
Just started 3 days ago
.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Run by Owner at 11:40:57 on 2011-05-23
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.54 [GMT -4:00]
.
AV: Norton AntiVirus *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
.
============== Running Processes ===============
.
D:\WINDOWS\system32\svchost -k DcomLaunch
D:\WINDOWS\system32\svchost -k rpcss
D:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
D:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
D:\WINDOWS\system32\svchost.exe -k NetworkService
D:\WINDOWS\system32\svchost.exe -k LocalService
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
D:\WINDOWS\system32\svchost.exe -k imgsvc
D:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe
D:\Program Files\Trusteer\Rapport\bin\RapportService.exe
D:\WINDOWS\System32\alg.exe
D:\Program Files\Analog Devices\Core\smax4pnp.exe
D:\WINDOWS\system32\igfxpers.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
D:\Program Files\MagicDisc\MagicDisc.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
D:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Documents and Settings\Owner\My Documents\Downloads\dds.scr
D:\WINDOWS\system32\WSCRIPT.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Connection Wizard,ShellNext = "d:\program files\outlook express\msimn.exe" //mailurl:mailto:contact@buprenorphine-doctors.com
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - d:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - d:\program files\norton antivirus\engine\17.8.0.5\IPSBHO.DLL
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "d:\program files\common files\nero\lib\NMBgMonitor.exe"
mRun: [SoundMAXPnP] d:\program files\analog devices\core\smax4pnp.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [igfxtray] d:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] d:\windows\system32\hkcmd.exe
mRun: [igfxpers] d:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "d:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "d:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [HotKeysCmds] d:\windows\system32\hkcmd.exe
mRun: [Persistence] d:\windows\system32\igfxpers.exe
StartupFolder: d:\docume~1\owner\startm~1\programs\startup\magicdisc.lnk - d:\program files\magicdisc\MagicDisc.exe
mPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: Download with ImTOO iPhone Transfer Platinum - d:\program files\imtoo\iphone transfer platinum\upod_link.HTM
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: hrblock.com\taxes
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - d:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - d:\documents and settings\owner\application data\mozilla\firefox\profiles\kor9yvwe.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: d:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.5.0.127\ipsffplgn\components\IPSFFPl.dll
FF - plugin: d:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - d:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - d:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Norton IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - d:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.5.0.127\IPSFFPlgn
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
.
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
============= SERVICES / DRIVERS ===============
.
R0 RapportKELL;RapportKELL;d:\windows\system32\drivers\RapportKELL.sys [2011-4-28 53816]
R0 SymDS;Symantec Data Store;d:\windows\system32\drivers\nav\1108000.005\symds.sys [2010-11-15 328752]
R0 SymEFA;Symantec Extended File Attributes;d:\windows\system32\drivers\nav\1108000.005\symefa.sys [2010-11-15 173104]
R1 BHDrvx86;BHDrvx86;d:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.5.0.127\definitions\bashdefs\20110518.001\BHDrvx86.sys [2011-5-19 802936]
R1 ccHP;Symantec Hash Provider;d:\windows\system32\drivers\nav\1108000.005\cchpx86.sys [2010-11-15 501888]
R1 RapportCerberus_26169;RapportCerberus_26169;d:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportcerberus\26169\RapportCerberus_26169.sys [2011-5-2 57144]
R1 RapportEI;RapportEI;d:\program files\trusteer\rapport\bin\RapportEI.sys [2011-4-28 66360]
R1 RapportPG;RapportPG;d:\program files\trusteer\rapport\bin\RapportPG.sys [2011-4-28 158904]
R1 SymIRON;Symantec Iron Driver;d:\windows\system32\drivers\nav\1108000.005\ironx86.sys [2010-11-15 116784]
R2 NAV;Norton AntiVirus;d:\program files\norton antivirus\engine\17.8.0.5\ccsvchst.exe [2010-11-15 126392]
R2 RapportMgmtService;Rapport Management Service;d:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2011-4-28 870200]
R2 StarWindServiceAE;StarWind AE Service;d:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2009-12-23 370688]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;d:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-5-9 105592]
R3 IDSxpx86;IDSxpx86;d:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.5.0.127\definitions\ipsdefs\20110518.001\IDSXpx86.sys [2011-5-19 341944]
R3 NAVENG;NAVENG;d:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.5.0.127\definitions\virusdefs\20110522.002\NAVENG.SYS [2011-5-22 86008]
R3 NAVEX15;NAVEX15;d:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.5.0.127\definitions\virusdefs\20110522.002\NAVEX15.SYS [2011-5-22 1542392]
R3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;d:\windows\system32\drivers\rt2870.sys [2010-12-4 709248]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;d:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 DfSdkS;Defragmentation-Service;d:\program files\ashampoo\ashampoo winoptimizer 2010 advanced\DfSdkS.exe [2010-11-15 406016]
S3 MSFT43XX;Microsoft Wireless Notebook Adapter Driver;d:\windows\system32\drivers\mn720-50.sys [2003-7-18 254208]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;d:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-05-22 19:42:19 92160 ----a-w- d:\windows\system32\drivers\mcdbus.sys
2011-05-22 19:42:05 -------- d-----w- d:\program files\MagicDisc
2011-05-22 00:01:29 94208 --sha-r- d:\windows\system32\WMVXENCDP.dll
2011-05-21 05:05:50 135168 ----a-w- d:\windows\system32\igfxres.dll
2011-05-21 05:00:04 -------- d-----w- d:\documents and settings\owner\application data\Black Sea Studios
2011-05-20 04:01:09 -------- d-----w- d:\documents and settings\owner\application data\.minecraft
2011-05-15 02:55:46 -------- d-----w- d:\program files\Activision
2011-05-15 02:51:06 -------- d-----w- d:\program files\Alcohol Soft
2011-05-15 02:45:24 436792 ----a-w- d:\windows\system32\drivers\sptd.sys
2011-04-28 18:34:50 53816 ----a-w- d:\windows\system32\drivers\RapportKELL.sys
2011-04-28 00:40:53 -------- d-----w- d:\program files\Studio 3
.
==================== Find3M ====================
.
2011-04-18 00:49:16 20480 ----a-w- d:\windows\system32\H@tKeysH@@k.DLL
2011-04-03 14:47:04 2829 ----a-w- d:\windows\War3Unin.pif
2011-04-03 14:47:03 139264 ----a-w- d:\windows\War3Unin.exe
2011-03-07 05:31:47 692736 ----a-w- d:\windows\system32\inetcomm.dll
2011-03-04 06:35:38 420864 ----a-w- d:\windows\system32\vbscript.dll
2011-03-03 13:27:43 1866880 ----a-w- d:\windows\system32\win32k.sys
2011-02-22 23:06:29 916480 ----a-w- d:\windows\system32\wininet.dll
2011-02-22 23:06:29 43520 ----a-w- d:\windows\system32\licmgr10.dll
2011-02-22 23:06:29 1469440 ----a-w- d:\windows\system32\inetcpl.cpl
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD1600JB-75GVC0 rev.08.02D08 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x82F046F0]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x82f0aa10]; MOV EAX, [0x82f0aa8c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x82FA3AB8]
3 CLASSPNP[0xF86F7FD7] -> nt!IofCallDriver[0x804E37D5] -> [0x82F95838]
\Driver\atapi[0x82F934B0] -> IRP_MJ_CREATE -> 0x82F046F0
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x82F0453B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 11:43:56.54 ===============
attach.txt (10.13K)
Number of downloads: 1
Attached File(s)
-
ark.txt (20.47K)
Number of downloads: 0

Help
This topic is locked


Back to top










