Kaspersky became corrupted and had to be uninstalled and reinstalled. There was at least 30 minutes when the
computer was unprotected. Notices about attempts to install Sinowal on Drive 0 have stopped, but I suspect it may
have now installed itself in the MBR. ComboFix was run successfully. The log is posted below:
ComboFix 12-01-09.07 - Chuck 01/09/2012 19:28:39.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.275 [GMT -7:00]
Running from: c:\documents and settings\Chuck\Desktop\ComboFix.exe
AV: Kaspersky PURE *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky PURE *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
.
.
((((((((((((((((((((((((( Files Created from 2011-12-10 to 2012-01-10 )))))))))))))))))))))))))))))))
.
.
2012-01-09 02:50 . 2010-10-02 05:05 162392 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
2012-01-09 02:50 . 2012-01-09 03:05 115369 ----a-w- c:\windows\system32\drivers\klin.dat
2012-01-09 02:50 . 2012-01-09 03:05 97961 ----a-w- c:\windows\system32\drivers\klick.dat
2012-01-09 02:48 . 2012-01-09 02:48 -------- d-----w- c:\program files\Common Files\InfoWatch
2012-01-09 02:48 . 2012-01-09 02:48 -------- d-----w- c:\program files\Kaspersky Lab
2012-01-09 02:46 . 2012-01-09 02:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2012-01-01 03:00 . 2011-12-21 07:24 121816 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2012-01-01 03:00 . 2011-12-21 07:24 97240 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2012-01-01 03:00 . 2011-12-21 07:24 814040 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2012-01-01 03:00 . 2011-12-21 07:24 486360 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2012-01-01 03:00 . 2011-12-21 07:24 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll
2012-01-01 03:00 . 2011-12-21 07:24 2124760 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2012-01-01 03:00 . 2011-12-21 07:24 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2012-01-01 03:00 . 2011-12-21 04:30 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2012-01-01 03:00 . 2011-12-21 04:30 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2012-01-01 03:00 . 2011-12-21 04:30 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-01-01 03:00 . 2011-12-21 04:30 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-01-01 03:00 . 2011-12-21 04:30 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-01-01 02:35 . 2011-08-30 20:33 95672 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-12-31 14:25 . 2011-12-31 14:25 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2011-12-31 14:17 . 2012-01-01 02:15 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2011-12-30 14:12 . 2011-12-30 14:12 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2011-12-30 14:07 . 2011-12-30 14:07 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-12-13 16:14 . 2011-12-13 16:14 -------- d-----w- c:\program files\Common Files\Java
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-10 22:24 . 2009-11-20 21:42 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-23 13:25 . 2004-08-11 23:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-10 12:54 . 2010-05-12 13:27 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-10 10:27 . 2010-05-12 13:27 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-11-04 19:20 . 2004-08-11 23:00 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2004-08-11 23:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2004-08-11 23:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-11 23:00 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2004-08-11 23:00 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-11 23:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2004-08-11 23:00 2148864 ------w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-04 04:59 2027008 ------w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 21:29 . 2011-10-24 21:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 21:29 . 2011-10-24 21:29 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-10-18 11:13 . 2004-08-11 23:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-12-21 07:24 . 2012-01-01 03:00 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2012-01-04_02.03.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-01-10 02:39 . 2012-01-10 02:39 16384 c:\windows\Temp\Perflib_Perfdata_338.dat
- 2011-02-16 15:09 . 2009-12-14 19:44 39352 c:\windows\system32\DRVSTORE\CSVirtualD_3B3E94D8DD0D576D0A23AD0122A66962165484F1\wnet\x86\CSVirtualDiskDrv.sys
+ 2012-01-09 02:49 . 2009-12-14 19:44 39352 c:\windows\system32\DRVSTORE\CSVirtualD_3B3E94D8DD0D576D0A23AD0122A66962165484F1\wnet\x86\CSVirtualDiskDrv.sys
+ 2012-01-09 02:49 . 2009-12-14 19:44 88632 c:\windows\system32\DRVSTORE\CSVirtualD_3B3E94D8DD0D576D0A23AD0122A66962165484F1\w2k\x86\CSCrySec.sys
- 2011-02-16 15:09 . 2009-12-14 19:44 88632 c:\windows\system32\DRVSTORE\CSVirtualD_3B3E94D8DD0D576D0A23AD0122A66962165484F1\w2k\x86\CSCrySec.sys
+ 2012-01-09 02:49 . 2009-12-14 19:44 88632 c:\windows\system32\DRVSTORE\CSCrySec_3B3E94D8DD0D576D0A23AD0122A66962165484F1\w2k\x86\CSCrySec.sys
- 2011-02-16 15:09 . 2009-12-14 19:44 88632 c:\windows\system32\DRVSTORE\CSCrySec_3B3E94D8DD0D576D0A23AD0122A66962165484F1\w2k\x86\CSCrySec.sys
- 2011-02-16 15:06 . 2011-02-16 15:06 315408 c:\windows\system32\drivers\klif.sys
+ 2012-01-09 02:47 . 2012-01-09 02:47 315408 c:\windows\system32\drivers\klif.sys
+ 2012-01-09 02:50 . 2012-01-09 02:50 5665792 c:\windows\Installer\f077c.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\KAVOverlayIcon]
@="{dd230880-495a-11d1-b064-008048ec2fc5}"
[HKEY_CLASSES_ROOT\CLSID\{dd230880-495a-11d1-b064-008048ec2fc5}]
2010-10-02 05:05 129624 ----a-w- c:\program files\Kaspersky Lab\Kaspersky PURE\shellex.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-30 282624]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"PMX Daemon"="ICO.EXE" [2006-11-08 49152]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-06-23 53248]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2011-08-30 624056]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-09-24 49152]
"ISUSPM Startup"="c:\progra~1\common~1\instal~1\update~1\isuspm.exe" [2004-07-27 221184]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-06 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-11-13 421736]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky PURE\avp.exe" [2010-10-02 348760]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-9-24 282624]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-11-4 176128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"2479:TCP"= 2479:TCP:Services
"3246:TCP"= 3246:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop
"9302:TCP"= 9302:TCP:Services
.
R0 CSCrySec;InfoWatch Encrypt Sector Library driver;c:\windows\system32\drivers\CSCrySec.sys [2/16/2011 8:09 AM 88632]
R0 KLBG;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [10/14/2009 9:18 PM 36880]
R1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;c:\windows\system32\drivers\CSVirtualDiskDrv.sys [2/16/2011 8:09 AM 39352]
R2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [3/17/2006 4:25 PM 65536]
R2 CSObjectsSrv;CryptoStorage control service;c:\program files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [12/21/2009 5:34 PM 743992]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [9/14/2009 2:42 PM 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [10/2/2009 7:39 PM 19472]
S1 aswSP;avast! Self Protection; [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys --> c:\windows\system32\DRIVERS\aswFsBlk.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/30/2011 7:07 AM 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [12/30/2011 7:07 AM 136176]
S3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2/5/2007 7:43 PM 18432]
S3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2/5/2007 7:43 PM 14336]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 00:57]
.
2012-01-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-30 14:06]
.
2012-01-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-30 14:06]
.
2012-01-10 c:\windows\Tasks\SDMsgUpdate (SD).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2008-10-23 14:29]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://msnbc.com/
uInternet Settings,ProxyOverride = *.local
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm
TCP: DhcpNameServer = 192.168.1.1
DPF: {B8E73359-3422-4384-8D27-4EA1B4C01232} - hxxps://krmcvpn.azkrmc.org/+CSCOL+/cscopf.cab
FF - ProfilePath - c:\documents and settings\Chuck\Application Data\Mozilla\Firefox\Profiles\5v9ee450.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msnbc.msn.com/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-01-09 19:40
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(1316)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\HPZipm12.exe
c:\windows\stsystra.exe
c:\windows\system32\ICO.EXE
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2012-01-09 19:44:50 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-10 02:44
ComboFix2.txt 2012-01-04 02:09
ComboFix3.txt 2010-03-03 17:47
ComboFix4.txt 2010-03-03 06:22
ComboFix5.txt 2012-01-10 02:27
.
Pre-Run: 133,763,436,544 bytes free
Post-Run: 133,898,756,096 bytes free
.
- - End Of File - - EFC4B80740E70EC57CF042266B6A6E8F
ComputerArt