Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Suspected Vundo and other infections


  • This topic is locked This topic is locked
11 replies to this topic

#1 kannan1606

kannan1606

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:17 PM

Posted 31 May 2009 - 10:37 PM

First of all, I had Kaspersky as my Antivirus program and I was not able to update it even though I had the key with me, I tried doing it and the AV showed "Invalid Key" message. Since, there were no updates happening, my laptop started functioning in a manner that caused a suspicion in me of the laptop being infected by viruses. It showed plenty of error messages like the following

"0 MB disk space in C drive"( although i was sure that i was having almost 2 GB space in the drive and then at last I managed to create 500 MB space)
KAV was giving messages of a process trying to attach itself into explorer.exe when i try to open any drive
Also many of the Word files are reporting that they are corrupted.
There is also a minor problem, when I open any drive from my computer, it opens in a new window instead of in the same window of "My Computer''.
Since KAV was not updating I uninstalled it and installed Avast, Avast detected one file which called itself Q9.cmd which Avast by heuristic analysis called rootkit.I deleted it. I also removed lot of infections by Spybot, Malware Bytes, Super Antispyware etc. But I wish to submit my log here for further analysis.

--------------------


DDS (Ver_09-05-14.01) - FAT32x86
Run by SURAJ at 8:30:04.43 on Mon 06/01/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1537 [GMT 5.5:30]

AV: avast! antivirus 4.8.1296 [VPS 090115-0] *On-access scanning enabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
SVCHOST.EXE
C:\WINDOWS\System32\svchost.exe -k netsvcs
SVCHOST.EXE
SVCHOST.EXE
E:\Alwil Software\Avast4\aswUpdSv.exe
E:\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\O2Micro Oz128 Driver\o2flash.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
E:\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Documents and Settings\SURAJ\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
E:\Alwil Software\Avast4\ashMaiSv.exe
E:\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\CNAB3RPK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
E:\Alwil Software\Avast4\setup\avast.setup
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\SURAJ\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\SURAJ\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\SURAJ\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\SURAJ\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = local
uInternet Settings,ProxyServer = 127.0.0.1:9666
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: FGCatchUrl: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - d:\flashget\jccatch.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: FlashGet GetFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - d:\flashget\getflash.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uRun: [Google Update] "c:\documents and settings\suraj\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [cdoosoft] c:\windows\system32\olhrwef.exe
mRun: [Msmsgs] c:\windows\system32\Msmsgs.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
mRun: [NWEReboot]
mRun: [avast!] e:\alwils~1\avast4\ashDisp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
IE: &Download All with FlashGet - d:\flashget\jc_all.htm
IE: &Download with FlashGet - d:\flashget\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - d:\flashget\FlashGet.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Notify: !SASWinLogon - e:\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - e:\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\suraj\applic~1\mozilla\firefox\profiles\igl9yqps.default\
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\suraj\local settings\application data\google\update\1.2.145.5\npGoogleOneClick8.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-5-31 111184]
R1 klif;Klif;c:\windows\system32\drivers\klif.sys [2007-11-9 193296]
R1 SASDIFSV;SASDIFSV;e:\superantispyware\sasdifsv.sys [2009-4-28 9968]
R1 SASKUTIL;SASKUTIL;e:\superantispyware\SASKUTIL.SYS [2009-4-28 72944]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-31 20560]
R2 avast! Antivirus;avast! Antivirus;e:\alwil software\avast4\ashServ.exe [2009-5-31 155160]
R3 avast! Mail Scanner;avast! Mail Scanner;e:\alwil software\avast4\ashMaiSv.exe [2009-5-31 254040]
R3 avast! Web Scanner;avast! Web Scanner;e:\alwil software\avast4\ashWebSv.exe [2009-5-31 352920]
S3 AVPsys;AVPsys;\??\c:\windows\system32\drivers\cdaudio.sys --> c:\windows\system32\drivers\cdaudio.sys [?]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-12-23 30192]
S3 SASENUM;SASENUM;e:\superantispyware\SASENUM.SYS [2009-4-28 7408]

=============== Created Last 30 ================

2009-06-01 07:58 93,184 ---shr-- c:\windows\system32\nmdfgds0.dll
2009-05-31 21:06 105,555 ---shr-- c:\windows\system32\olhrwef.exe
2009-05-31 20:38 <DIR> --dsh--- C:\FOUND.000
2009-05-31 18:46 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-05-31 18:37 <DIR> --d----- c:\docume~1\suraj\applic~1\SUPERAntiSpyware.com
2009-05-31 18:34 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-05-31 18:16 540,672 a--sh--- c:\windows\system32\drivers\fidbox.dat
2009-05-31 18:16 3,572 a--sh--- c:\windows\system32\drivers\fidbox.idx
2009-05-31 18:16 3,332 a--sh--- c:\windows\system32\drivers\fidbox2.idx
2009-05-31 18:16 2,336 a--sh--- c:\windows\system32\drivers\fidbox2.dat
2009-05-31 18:07 105,555 ---shr-- C:\q9.cmd
2009-05-31 17:48 0 a------- C:\Temp
2009-05-31 17:45 <DIR> --d----- C:\VundoFix Backups
2009-05-31 17:29 0 a------- C:\icon_chanceofsleet.png
2009-05-31 17:28 0 a------- C:\icon_chanceofrain.png
2009-05-31 17:28 0 a------- C:\hover_glow.png
2009-05-31 17:27 0 a------- C:\gd_weather_thunderstorm.png
2009-05-31 17:27 0 a------- C:\gd_weather_sunnyNight.png
2009-05-31 17:27 0 a------- C:\undocked-sunny.png
2009-05-31 17:27 0 a------- C:\gd_weather_storm.png
2009-05-31 17:27 0 a------- C:\gd_weather_sleet.png
2009-05-31 17:26 0 a------- C:\gd_weather_rain.png
2009-05-31 17:26 0 a------- C:\gd_weather_mostlySunnyNight.png
2009-05-31 17:26 0 a------- C:\gd_weather_mostlySunnyDay.png
2009-05-31 17:25 0 a------- C:\gd_weather_mostlyCloudyNight.png
2009-05-31 17:25 0 a------- C:\gd_weather_mostlyCloudyDay.png
2009-05-31 17:25 0 a------- C:\gd_weather_icy.png
2009-05-31 17:25 0 a------- C:\gd_weather_haze.png
2009-05-31 17:25 0 a------- C:\gd_weather_fog.png
2009-05-31 17:24 0 a------- C:\gd_weather_flurries.png
2009-05-31 17:24 0 a------- C:\gd_weather_cloudy.png
2009-05-31 17:24 0 a------- C:\slate_open.png
2009-05-31 17:24 0 a------- C:\slate_main.png
2009-05-31 09:57 <DIR> --d----- c:\docume~1\suraj\applic~1\Malwarebytes
2009-05-31 09:57 17,200 a------- c:\windows\system32\drivers\mbam.sys
2009-05-31 09:57 38,528 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-31 09:57 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-05-31 09:44 105,774 ---shr-- C:\ymxf2.exe
2009-05-06 19:42 8,704 a------- c:\windows\system32\kbdjpn.dll
2009-05-06 19:42 8,704 a------- c:\windows\system32\dllcache\kbdjpn.dll
2009-05-06 19:42 8,192 a------- c:\windows\system32\kbdkor.dll
2009-05-06 19:42 8,192 a------- c:\windows\system32\dllcache\kbdkor.dll
2009-05-06 19:42 6,144 a------- c:\windows\system32\kbd106.dll
2009-05-06 19:42 6,144 a------- c:\windows\system32\kbd101c.dll
2009-05-06 19:42 6,144 a------- c:\windows\system32\dllcache\kbd106.dll
2009-05-06 19:42 6,144 a------- c:\windows\system32\dllcache\kbd101c.dll
2009-05-06 19:42 5,632 a------- c:\windows\system32\kbd103.dll
2009-05-06 19:42 5,632 a------- c:\windows\system32\dllcache\kbd103.dll
2009-05-06 19:42 6,144 a------- c:\windows\system32\kbd101b.dll
2009-05-06 19:42 6,144 a------- c:\windows\system32\dllcache\kbd101b.dll

==================== Find3M ====================

2009-05-22 20:52 138,184 a------- c:\windows\system32\drivers\PnkBstrK.sys
2009-05-22 20:52 183,112 a------- c:\windows\system32\PnkBstrB.exe
2009-04-12 21:11 4,096 a------- c:\windows\d3dx.dat
2006-10-16 04:27 4,253,184 a------- c:\program files\mplayerc.exe

============= FINISH: 8:30:33.35 ===============


--------------

Thank you, and I appreciate any help you could provide me. :thumbup2:

Suraj

Attached Files



BC AdBot (Login to Remove)

 


#2 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:12:47 AM

Posted 01 June 2009 - 08:51 PM

Hello, kannan1606 :)
:thumbup2: to BleepingComputer.com

My name is Billy O'Neal and I will be helping you. (Billy or Bill is fine, if you like.)
Please give me some time to look over your computer's log(s).
Please take note of the following:
  • In the meantime, please refrain from making any changes to your computer.
  • Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. :)
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Finally, please reply using the Posted Image button in the lower right hand corner of your screen.
We need to scan for Rootkits with GMER
  • Please download GMER from one of the following locations, and save it to your desktop:
    • Main Mirror
      This version will download a randomly named file (Recommended)
    • Zip Mirror
      This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Close any and all open programs, as this process may crash your computer.
  • Double click Posted Image or Posted Image on your desktop.
  • Allow the gmer.sys driver to load if asked.
  • You may see this window. If you do, click No.
    Posted Image
  • Click on Posted Image and wait for the scan to finish.
  • If you see a rootkit warning window, click OK.
  • Push Posted Image and save the logfile to your desktop.
  • Copy and Paste the contents of that file in your next post.
In your next reply, please include the following:
  • GMER's Log

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#3 kannan1606

kannan1606
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:17 PM

Posted 02 June 2009 - 12:40 AM

Hi Bill,

The forum says that my post is too big so I am attaching the log, as I could not find a suitable place to divide it in half.

Thanks for the fast reply,
Suraj

Attached Files

  • Attached File  gmer.log   413.7KB   2 downloads


#4 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:12:47 AM

Posted 02 June 2009 - 06:37 AM

Hello, kannan1606 :thumbup2:
We Need to Run ComboFix

Note to readers of this post other than the starter of this thread:
ComboFix is a VERY POWERFUL tool which should NOT BE USED without guidance of an expert.

If this tool helped you, please consider a donation to it's author: Posted Image

How to run ComboFix:
  • Please download ComboFix from one of the following mirrors, and save it to your desktop.
  • Disable any running Anti-Virus or Anti-Malware programs. This includes Firewalls, Anti-Virus, Spyware Scanners, etc. Any or all of them may interfere with the running of ComboFix.
  • Double click Posted Image on your desktop.
  • Read and accept (Press Yes) to the disclaimer.
  • For Windows XP Systems: Install the Recovery Console:
    • If you are using Windows XP and do not already have the Recovery Console installed, please ensure your internet connection is active (if possible), and press Yes. If for some reason your internet is not working, please press No. If you are not using Windows XP, you will not be prompted.
    • When prompted to accept the EULA, press OK.
    • Accept Microsoft's EULA (Press Yes).
    • When you are told that the RC is installed correctly, please press YES to continue scanning for malware.
  • ComboFix will run. Simply wait for it to finish.
  • When it finishes, ComboFix will produce a log. Please post that log in your next reply here :)
NOTE: If ComboFix will not run, please rename it to GlobRemover.exe and try again!

In your next reply, please include the following:
  • ComboFix.txt

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#5 kannan1606

kannan1606
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:17 PM

Posted 02 June 2009 - 10:05 AM

Hello Bill,

Here is the log from ComboFix

-------------------------
ComboFix 09-05-31.06 - SURAJ 06/02/2009 20:25.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1611 [GMT 5.5:30]
Running from: c:\documents and settings\SURAJ\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090601-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
C:\q9.cmd
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\olhrwef.exe
c:\windows\system32\setting.ini
c:\windows\system32\x64
C:\ymxf2.exe
D:\Autorun.inf
D:\q9.cmd
D:\ymxf2.exe
E:\Autorun.inf
E:\q9.cmd
E:\ymxf2.exe
F:\Autorun.inf
F:\q9.cmd
F:\ymxf2.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_AVPsys


((((((((((((((((((((((((( Files Created from 2009-05-02 to 2009-06-02 )))))))))))))))))))))))))))))))
.

2009-05-31 15:13 . 2009-02-05 21:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-05-31 15:13 . 2009-02-05 21:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-05-31 15:13 . 2009-02-05 21:05 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-05-31 15:13 . 2009-02-05 21:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-05-31 15:13 . 2009-02-05 21:08 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-05-31 15:13 . 2009-02-05 21:08 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-05-31 15:13 . 2009-02-05 21:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-05-31 15:13 . 2009-02-05 21:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-05-31 15:13 . 2009-02-05 21:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-05-31 15:08 . 2009-05-31 15:08 -------- d-sh--w- C:\FOUND.000
2009-05-31 13:29 . 2009-05-31 14:11 117760 ----a-w- c:\documents and settings\SURAJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-05-31 13:16 . 2009-05-31 13:16 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-31 13:07 . 2009-05-31 13:07 -------- d-----w- c:\documents and settings\SURAJ\Application Data\SUPERAntiSpyware.com
2009-05-31 13:04 . 2009-05-31 13:04 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-31 12:46 . 2009-06-02 14:59 540672 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-05-31 12:46 . 2009-06-02 14:59 5152 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-05-31 12:15 . 2009-05-31 12:15 -------- d-----w- C:\VundoFix Backups
2009-05-31 04:27 . 2009-05-31 04:27 -------- d-----w- c:\documents and settings\SURAJ\Application Data\Malwarebytes
2009-05-31 04:27 . 2008-09-09 18:33 17200 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-31 04:27 . 2008-09-09 18:34 38528 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-31 04:27 . 2009-05-31 04:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-06 14:12 . 2001-08-17 17:06 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2009-05-06 14:12 . 2001-08-17 17:06 8704 ----a-w- c:\windows\system32\dllcache\kbdjpn.dll
2009-05-06 14:12 . 2001-08-17 17:06 8192 ----a-w- c:\windows\system32\kbdkor.dll
2009-05-06 14:12 . 2001-08-17 17:06 8192 ----a-w- c:\windows\system32\dllcache\kbdkor.dll
2009-05-06 14:12 . 2001-08-17 09:25 6144 ----a-w- c:\windows\system32\kbd106.dll
2009-05-06 14:12 . 2001-08-17 09:25 6144 ----a-w- c:\windows\system32\kbd101c.dll
2009-05-06 14:12 . 2001-08-17 09:25 6144 ----a-w- c:\windows\system32\dllcache\kbd106.dll
2009-05-06 14:12 . 2001-08-17 09:25 6144 ----a-w- c:\windows\system32\dllcache\kbd101c.dll
2009-05-06 14:12 . 2001-08-17 09:25 5632 ----a-w- c:\windows\system32\kbd103.dll
2009-05-06 14:12 . 2001-08-17 09:25 5632 ----a-w- c:\windows\system32\dllcache\kbd103.dll
2009-05-06 14:12 . 2001-08-17 09:25 6144 ----a-w- c:\windows\system32\kbd101b.dll
2009-05-06 14:12 . 2001-08-17 09:25 6144 ----a-w- c:\windows\system32\dllcache\kbd101b.dll
2009-05-03 17:14 . 2006-12-14 04:30 110592 ----a-w- c:\documents and settings\SURAJ\Application Data\U3\temp\cleanup.exe
2009-05-03 17:13 . 2009-05-03 17:13 -------- d-----w- c:\documents and settings\SURAJ\Application Data\U3

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-02 14:59 . 2009-05-31 12:46 4340 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-02 14:59 . 2009-05-31 12:46 3644 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-05-22 15:22 . 2008-12-08 18:48 138184 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-05-22 15:22 . 2008-12-08 18:17 183112 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-04-12 15:41 . 2009-04-12 15:41 4096 ----a-w- c:\windows\d3dx.dat
2006-10-15 22:57 . 2008-08-13 14:06 4253184 ----a-w- c:\program files\mplayerc.exe
2008-12-23 17:34 . 2008-12-23 17:34 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

------- Sigcheck -------

[-] 2004-08-03 12:14 359040 6A603809F598332DBEDD535BDBCE313E c:\windows\system32\drivers\tcpip.sys
[7] 2004-08-03 12:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\system32\dllcache\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\SURAJ\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-10 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-12-23 30192]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"avast!"="e:\alwils~1\Avast4\ashDisp.exe" [2009-02-05 81000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-20 113664]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "e:\superantispyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 06:35 356352 ----a-w- e:\superantispyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL.EXE"=
"d:\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5/31/2009 8:43 PM 114768]
R1 SASDIFSV;SASDIFSV;e:\superantispyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]
R1 SASKUTIL;SASKUTIL;e:\superantispyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5/31/2009 8:43 PM 20560]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [12/23/2008 11:04 PM 30192]
S3 SASENUM;SASENUM;e:\superantispyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-05-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 09:27]

2009-06-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-861567501-602609370-725345543-1003.job
- c:\documents and settings\SURAJ\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-10 15:08]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-NWEReboot - (no file)
SafeBoot-procexp90.Sys


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = local
uInternet Settings,ProxyServer = 127.0.0.1:9666
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &Download All with FlashGet - d:\flashget\jc_all.htm
IE: &Download with FlashGet - d:\flashget\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\SURAJ\Application Data\Mozilla\Firefox\Profiles\igl9yqps.default\
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\SURAJ\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-02 20:30
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(616)
e:\superantispyware\SASWINLO.dll
.
------------------------ Other Running Processes ------------------------
.
e:\alwil software\Avast4\aswUpdSv.exe
e:\alwil software\Avast4\ashServ.exe
c:\program files\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
c:\program files\BONJOUR\MDNSRESPONDER.EXE
c:\program files\O2MICRO OZ128 DRIVER\O2FLASH.EXE
c:\windows\SYSTEM32\PNKBSTRA.EXE
c:\windows\SYSTEM32\CNAB3RPK.EXE
c:\program files\CYBERLINK\SHARED FILES\RICHVIDEO.EXE
e:\alwil software\Avast4\ashMaiSv.exe
e:\alwil software\Avast4\ashWebSv.exe
c:\program files\IPOD\BIN\IPODSERVICE.EXE
c:\windows\SYSTEM32\WSCNTFY.EXE
.
**************************************************************************
.
Completion time: 2009-06-02 20:31 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-02 15:01

Pre-Run: 498,548,736 bytes free
Post-Run: 439,320,576 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

184

#6 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:12:47 AM

Posted 03 June 2009 - 10:06 PM

Hello, kannan1606 :thumbup2:
We need to re-run ComboFix with some additonal directives.
  • Please disable any running anti-virus programs.

    If you are unsure how to do this, see this topic: http://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the quotebox below into it:
    FCOPY::
    c:\windows\system32\dllcache\tcpip.sys | c:\windows\system32\drivers\tcpip.sys
  • Save this as CFScript.txt, in the same location as ComboFix.exe
  • Posted Image
    Refering to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at "C:\ComboFix.txt". Please copy and paste that report here.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

I would like us to use ESET (NOD32)'s Online Scanner
  • Please go to ESET OnlineScan (NOD32)
  • You will then see the Terms of Use, tick the check-box infront of YES, I accept the Terms of Use
  • Now click Start
  • Should you face a Security Warning that asks if you want to install and run a file called "OnlineScanner.cab", click Yes
  • Click Start
    • Note: (the Onlinescanner will now prepare itself for running on your pc)
  • To do a full-scan, tick: "Remove found threats" and "Scan potentially unwanted applications"
  • Press Scan
  • The Onlinescan will now start and scan your pc (this could take a while)
  • When the scan has finished, it will show a screen with two tabs "overview" and "details" and the option to get information or buy software, just close the window
  • Click Start >> Run... >> type: C:\Program Files\EsetOnlineScanner\log.txt
  • The Scanresults will now open in Notepad
  • Click into the text area, right-click and chose "select all" (or use +A)
  • Right-click again and chose "Copy" (or +C)
  • Close/Exit Notepad
  • Navigate to this thread and post your log along with anything else requested from us, by right-clicking and "paste" (or ctrl+v) in the text area of the reply post you just created.
Note: For Vista Users: Eset is compatible but Internet Explorer must be run as Administrator. To do this, right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select "Run as Administrator" from the context menu.)

In your next reply, please include the following:
  • ComboFix.txt
  • ESET OnlineScan's Log

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#7 kannan1606

kannan1606
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:17 PM

Posted 04 June 2009 - 07:39 AM

Billy,

The online scanner is not running properly; it loads for a while and then asks me to install the ActiveX Control. But when I click to install it, it says that the information cannot be resent without refreshing the page. This just goes on and on and on.

Combofix, however, ran as needed. Here is the log :

-----------
ComboFix 09-05-31.06 - SURAJ 06/04/2009 8:42.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1603 [GMT 5.5:30]
Running from: c:\documents and settings\SURAJ\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\SURAJ\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090602-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
--------------- FCopy ---------------

c:\windows\system32\dllcache\tcpip.sys --> c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((( Files Created from 2009-05-04 to 2009-06-04 )))))))))))))))))))))))))))))))
.

2009-06-03 16:29 . 2009-06-03 16:29 108144 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-05-31 15:13 . 2009-02-05 21:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-05-31 15:13 . 2009-02-05 21:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-05-31 15:13 . 2009-02-05 21:05 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-05-31 15:13 . 2009-02-05 21:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-05-31 15:13 . 2009-02-05 21:08 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-05-31 15:13 . 2009-02-05 21:08 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-05-31 15:13 . 2009-02-05 21:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-05-31 15:13 . 2009-02-05 21:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-05-31 15:13 . 2009-02-05 21:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-05-31 15:08 . 2009-05-31 15:08 -------- d-sh--w- C:\FOUND.000
2009-05-31 13:29 . 2009-05-31 14:11 117760 ----a-w- c:\documents and settings\SURAJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-05-31 13:16 . 2009-05-31 13:16 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-31 13:07 . 2009-05-31 13:07 -------- d-----w- c:\documents and settings\SURAJ\Application Data\SUPERAntiSpyware.com
2009-05-31 13:04 . 2009-05-31 13:04 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-31 12:46 . 2009-06-03 17:22 540672 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-05-31 12:46 . 2009-06-03 17:22 12832 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-05-31 12:15 . 2009-05-31 12:15 -------- d-----w- C:\VundoFix Backups
2009-05-31 04:27 . 2009-05-31 04:27 -------- d-----w- c:\documents and settings\SURAJ\Application Data\Malwarebytes
2009-05-31 04:27 . 2008-09-09 18:33 17200 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-31 04:27 . 2008-09-09 18:34 38528 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-31 04:27 . 2009-05-31 04:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-06 14:12 . 2001-08-17 17:06 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2009-05-06 14:12 . 2001-08-17 17:06 8704 ----a-w- c:\windows\system32\dllcache\kbdjpn.dll
2009-05-06 14:12 . 2001-08-17 17:06 8192 ----a-w- c:\windows\system32\kbdkor.dll
2009-05-06 14:12 . 2001-08-17 17:06 8192 ----a-w- c:\windows\system32\dllcache\kbdkor.dll
2009-05-06 14:12 . 2001-08-17 09:25 6144 ----a-w- c:\windows\system32\kbd106.dll
2009-05-06 14:12 . 2001-08-17 09:25 6144 ----a-w- c:\windows\system32\kbd101c.dll
2009-05-06 14:12 . 2001-08-17 09:25 6144 ----a-w- c:\windows\system32\dllcache\kbd106.dll
2009-05-06 14:12 . 2001-08-17 09:25 6144 ----a-w- c:\windows\system32\dllcache\kbd101c.dll
2009-05-06 14:12 . 2001-08-17 09:25 5632 ----a-w- c:\windows\system32\kbd103.dll
2009-05-06 14:12 . 2001-08-17 09:25 5632 ----a-w- c:\windows\system32\dllcache\kbd103.dll
2009-05-06 14:12 . 2001-08-17 09:25 6144 ----a-w- c:\windows\system32\kbd101b.dll
2009-05-06 14:12 . 2001-08-17 09:25 6144 ----a-w- c:\windows\system32\dllcache\kbd101b.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-03 17:22 . 2009-05-31 12:46 5516 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-03 17:22 . 2009-05-31 12:46 4340 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-05-22 15:22 . 2008-12-08 18:48 138184 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-05-22 15:22 . 2008-12-08 18:17 183112 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-05-03 17:13 . 2009-05-03 17:13 -------- d-----w- c:\documents and settings\SURAJ\Application Data\U3
2009-04-12 15:41 . 2009-04-12 15:41 4096 ----a-w- c:\windows\d3dx.dat
2006-10-15 22:57 . 2008-08-13 14:06 4253184 ----a-w- c:\program files\mplayerc.exe
2008-12-23 17:34 . 2008-12-23 17:34 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-02_15.00.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-03 10:37 . 2009-06-03 10:37 16384 c:\windows\Temp\Perflib_Perfdata_514.dat
- 2009-02-02 13:25 . 2009-02-02 13:25 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\SURAJ\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-10 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-12-23 30192]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"avast!"="e:\alwils~1\Avast4\ashDisp.exe" [2009-02-05 81000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-20 113664]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "e:\superantispyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 06:35 356352 ----a-w- e:\superantispyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL.EXE"=
"d:\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5/31/2009 8:43 PM 114768]
R1 SASDIFSV;SASDIFSV;e:\superantispyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]
R1 SASKUTIL;SASKUTIL;e:\superantispyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5/31/2009 8:43 PM 20560]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [12/23/2008 11:04 PM 30192]
S3 SASENUM;SASENUM;e:\superantispyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-05-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 09:27]

2009-06-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-861567501-602609370-725345543-1003.job
- c:\documents and settings\SURAJ\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-10 15:08]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = local
uInternet Settings,ProxyServer = 127.0.0.1:9666
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &Download All with FlashGet - d:\flashget\jc_all.htm
IE: &Download with FlashGet - d:\flashget\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\SURAJ\Application Data\Mozilla\Firefox\Profiles\igl9yqps.default\
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\SURAJ\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-04 08:45
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(616)
e:\superantispyware\SASWINLO.dll
.
Completion time: 2009-06-04 8:46
ComboFix-quarantined-files.txt 2009-06-04 03:16
ComboFix2.txt 2009-06-02 15:01

Pre-Run: 314,064,896 bytes free
Post-Run: 305,184,768 bytes free

178

#8 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:12:47 AM

Posted 06 June 2009 - 03:03 AM

Hello, kannan1606 :thumbup2:
Please give this a shot instead then :)

We need to re-run ComboFix with some additonal directives.
  • Please disable any running anti-virus programs.

    If you are unsure how to do this, see this topic: http://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the quotebox below into it:
    DDS::
    uInternet Settings,ProxyServer = 127.0.0.1:9666
  • Save this as CFScript.txt, in the same location as ComboFix.exe
  • Posted Image
    Refering to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at "C:\ComboFix.txt". Please copy and paste that report here.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Please do an online scan with Kaspersky WebScanner.
  • Please visit the Kaspersky Online Scanner website.
    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
In your next reply, please include the following:
  • ComboFix.txt
  • Kaspersky's Log

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#9 kannan1606

kannan1606
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:17 PM

Posted 07 June 2009 - 10:16 AM

Hi Billy,

I had a bit of a hiccup with the Kaspersky scan; it crashed a couple of times, but in the end ran smoothly and found 4 infections.

Here are both the logs :

-----------

ComboFix 09-05-31.06 - SURAJ 06/06/2009 20:41.3 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1635 [GMT 5.5:30]
Running from: c:\documents and settings\SURAJ\Desktop\Bleeping Computer Files\ComboFix.exe
Command switches used :: c:\documents and settings\SURAJ\Desktop\Bleeping Computer Files\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090605-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-05-06 to 2009-06-06 )))))))))))))))))))))))))))))))
.

2009-06-04 05:24 . 2009-06-04 05:24 -------- d-----w- c:\documents and settings\SURAJ\Local Settings\Application Data\Electronic Arts
2009-06-04 03:47 . 2008-12-03 19:55 120832 ----a-w- c:\documents and settings\SURAJ\Application Data\Mozilla\Firefox\Profiles\igl9yqps.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll
2009-06-03 16:29 . 2009-06-03 16:29 108144 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-05-31 15:13 . 2009-02-05 21:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-05-31 15:13 . 2009-02-05 21:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-05-31 15:13 . 2009-02-05 21:05 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-05-31 15:13 . 2009-02-05 21:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-05-31 15:13 . 2009-02-05 21:08 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-05-31 15:13 . 2009-02-05 21:08 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-05-31 15:13 . 2009-02-05 21:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-05-31 15:13 . 2009-02-05 21:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-05-31 15:13 . 2009-02-05 21:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-05-31 15:08 . 2009-05-31 15:08 -------- d-sh--w- C:\FOUND.000
2009-05-31 13:29 . 2009-05-31 14:11 117760 ----a-w- c:\documents and settings\SURAJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-05-31 13:16 . 2009-05-31 13:16 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-31 13:07 . 2009-05-31 13:07 -------- d-----w- c:\documents and settings\SURAJ\Application Data\SUPERAntiSpyware.com
2009-05-31 13:04 . 2009-05-31 13:04 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-31 12:46 . 2009-06-06 07:51 540672 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-05-31 12:46 . 2009-06-06 07:51 23072 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-05-31 12:15 . 2009-05-31 12:15 -------- d-----w- C:\VundoFix Backups
2009-05-31 04:27 . 2009-05-31 04:27 -------- d-----w- c:\documents and settings\SURAJ\Application Data\Malwarebytes
2009-05-31 04:27 . 2008-09-09 18:33 17200 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-31 04:27 . 2008-09-09 18:34 38528 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-31 04:27 . 2009-05-31 04:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-06 07:51 . 2009-05-31 12:46 7508 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-06 07:51 . 2009-05-31 12:46 5300 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-05-22 15:22 . 2008-12-08 18:48 138184 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-05-22 15:22 . 2008-12-08 18:17 183112 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-05-03 17:13 . 2009-05-03 17:13 -------- d-----w- c:\documents and settings\SURAJ\Application Data\U3
2009-04-12 15:41 . 2009-04-12 15:41 4096 ----a-w- c:\windows\d3dx.dat
2006-10-15 22:57 . 2008-08-13 14:06 4253184 ----a-w- c:\program files\mplayerc.exe
2008-12-23 17:34 . 2008-12-23 17:34 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-02_15.00.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-06 15:05 . 2009-06-06 15:05 16384 c:\windows\Temp\Perflib_Perfdata_510.dat
- 2009-02-02 13:25 . 2009-02-02 13:25 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-03 16:15 . 2009-06-03 16:15 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-02 13:25 . 2009-02-02 13:25 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\SURAJ\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-10 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-12-23 30192]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"avast!"="e:\alwils~1\Avast4\ashDisp.exe" [2009-02-05 81000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-20 113664]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "e:\superantispyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 06:35 356352 ----a-w- e:\superantispyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL.EXE"=
"d:\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5/31/2009 8:43 PM 114768]
R1 SASDIFSV;SASDIFSV;e:\superantispyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]
R1 SASKUTIL;SASKUTIL;e:\superantispyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5/31/2009 8:43 PM 20560]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [12/23/2008 11:04 PM 30192]
S3 SASENUM;SASENUM;e:\superantispyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-05-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 09:27]

2009-06-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-861567501-602609370-725345543-1003.job
- c:\documents and settings\SURAJ\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-10 15:08]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &Download All with FlashGet - d:\flashget\jc_all.htm
IE: &Download with FlashGet - d:\flashget\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\SURAJ\Application Data\Mozilla\Firefox\Profiles\igl9yqps.default\
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\SURAJ\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-06 20:42
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(616)
e:\superantispyware\SASWINLO.dll
.
Completion time: 2009-06-06 20:43
ComboFix-quarantined-files.txt 2009-06-06 15:13
ComboFix2.txt 2009-06-04 03:16
ComboFix3.txt 2009-06-02 15:01

Pre-Run: 155,009,024 bytes free
Post-Run: 144,719,872 bytes free

163

------------


KASPERSKY ONLINE SCANNER 7.0 REPORT
Sunday, June 7, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Sunday, June 07, 2009 13:50:41
Records in database: 2322136
Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes
Scan area My Computer
C:\
D:\
E:\
F:\
G:\
I:\
Scan statistics
Files scanned 61044
Threat name 3
Infected objects 4
Suspicious objects 0
Duration of the scan 00:58:02

File name Threat name Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\nmdfgds0.dll.vir Infected: Trojan-GameThief.Win32.Magania.bfjs 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\olhrwef.exe.vir Infected: Trojan-GameThief.Win32.Magania.bevf 1
C:\Qoobox\Quarantine\C\ymxf2.exe.vir Infected: Trojan-GameThief.Win32.Magania.aztf 1
C:\Qoobox\Quarantine\C\q9.cmd.vir Infected: Trojan-GameThief.Win32.Magania.bevf 1
The selected area was scanned.

---------

#10 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:12:47 AM

Posted 08 June 2009 - 08:22 PM

Hello, kannan1606 :)
The infections were already removed by ComboFix. Uninstall it to finish removal.

Congratulations! You now appear clean! :thumbup2:

Are things running okay? Do you have any more questions?

System Still Slow?
You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.
If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware
We Need to Remove ComboFix
  • Please go to Start -> Run
  • Enter "ComboFix /u" (without quotes). Note the space betwen "ComboFix" and "/u", it needs to be there.
    Posted Image
  • Press OK (Or hit enter).
  • Allow ComboFix to remove itself.
We Need to Clean Up Our Mess
  • Please download OTCleanIt from one of the following mirrors and save it to your desktop:
  • Double click the Posted Image icon.
  • Push the large "Cleanup" button.
  • Allow your system to reboot.
Recommendations
Below are some recommendations to lower your chances of (re)infection.
  • Install Spyware Blaster and update it regularly
    If you wish, the commercial version provides automatic updating.
  • Install the MVPs hosts file, and update it regularly
    You can use the HostMan host file manager to do this automaticly if you wish.
    For more information on the hosts file, and what it can do for you, you can view the Tutorial on the Hosts file
  • Install an Anti-Spyware program, and update it regularly
    Malware Byte's Anti Malware is an excellent Anti-Spyware scanner. It's scan times are usually under ten minutes, and has excellent detection and removal rates.
    SUPERAntiSpyware is another good scanner with high detection and removal rates.
    Both programs are free for non commercial home use but provide a resident and do not nag if you purchase the paid versions.
  • Keep Windows (and your other Microsoft software) up to date!
    I cannot stress how important this is enough. Often holes are found in Internet Explorer or Windows itself that require patching. Sometimes these holes will allow an attacker unrestricted access to your computer.

    If you are using Windows XP or earlier
    Visit the Microsoft Update Website and follow the on screen instructions to setup Microsoft Update. Also follow the instructions to update your system. Please REBOOT and repeat this process until there are no more updates to install!!

    If you are using Windows Vista
    • Click the "Start Menu" (or Windows Orb)
    • Click "All Programs"
    • Click "Windows Update"
    • On the left, choose "Change Settings"
    • Ensure that the checkbox "Use Microsoft Update" at the bottom of the window is checked.
    • Press OK and accept the UAC prompt.
      Note: You shouldn't need to check this checkbox every single time you update, only the first time.
    • Click "Check for Updates" in the upper left corner.
    • Follow the instructions to install the latest updates.
    • Reboot and repeat the "Check for Updates" until there are no more critical updates to install
  • Keep your other software up to date as well
    Software does not need to be made by Microsoft to be insecure. You can use the Secunia Online Software occasionally to help you check for out of date software on your machine.
  • Stay up to date!
    The MOST IMPORTANT part of any security setup is keeping the software up to date. Malware writers release new variants every single day. If your software updates don't keep up, then the malware will always be one step ahead. Not a good thing :).
Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#11 kannan1606

kannan1606
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:17 PM

Posted 09 June 2009 - 12:34 AM

Hi Billy,

Thank you so much for your efforts. My laptop now seems to be clean, I am not getting any more error messages and it is running fast. I have read your recommendations and i will follow it too.

Suraj

#12 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:12:47 AM

Posted 09 June 2009 - 03:02 PM

Hello, kannan1606 :thumbup2:
Since this issue appears resolved, this topic has been closed.

If you need this topic reopened, please send me or another moderator a PM.

Everyone else please begin a new topic.

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users