It has disabled my Antivir AV, AVG anti-spyware, and Hijack this. When i try to run, I get an error message that says ... is not a valid win32 application. Re-install is not allowed by the infection as well.
I can run Super ASW, but it crashed my machine when it finds the culprit. I can't find a log file for it.
Also, can't get in to safe mode - whatever I have won't let me. I went to my previous thread and took the first step to save some time. I downloaded Combofix as disrected and ran it. Following is the log.
Thanks for any help.
ComboFix 08-02-25.3 - Big 2008-02-26 22:43:44.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2146 [GMT -5:00]
Running from: C:\Documents and Settings\Big\Desktop\Combo-Fix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\down
C:\WINDOWS\system32\drivers\down\277687.exe
C:\WINDOWS\system32\drivers\down\289015.exe
C:\WINDOWS\system32\drivers\down\289781.exe
C:\WINDOWS\system32\drivers\down\290921.exe
C:\WINDOWS\system32\drivers\down\327703.exe
C:\WINDOWS\system32\drivers\down\334109.exe
C:\WINDOWS\system32\drivers\down\335453.exe
C:\WINDOWS\system32\drivers\down\337093.exe
C:\WINDOWS\system32\drivers\down\339203.exe
C:\WINDOWS\system32\drivers\down\342484.exe
C:\WINDOWS\system32\drivers\down\344687.exe
C:\WINDOWS\system32\drivers\down\345187.exe
C:\WINDOWS\system32\drivers\down\348406.exe
C:\WINDOWS\system32\drivers\down\351359.exe
C:\WINDOWS\system32\drivers\down\352890.exe
C:\WINDOWS\system32\drivers\down\382812.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\srosa.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SROSA
-------\srosa
((((((((((((((((((((((((( Files Created from 2008-01-27 to 2008-02-27 )))))))))))))))))))))))))))))))
.
2008-02-26 22:29 . 2008-02-26 22:29 <DIR> d-------- C:\Program Files\Avira
2008-02-26 18:26 . 2008-02-26 18:26 <DIR> d-------- C:\Documents and Settings\Marc\Application Data\Grisoft
2008-02-23 21:35 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-23 14:43 . 2008-02-23 14:50 <DIR> d-------- C:\Temp\ZonedOut
2008-02-23 14:40 . 2008-02-23 14:40 <DIR> d-------- C:\Temp\MVPS-Hosts
2008-02-23 14:34 . 2008-02-23 14:34 <DIR> d-------- C:\Temp\ZoneAlarm
2008-02-23 00:24 . 2008-02-23 00:24 <DIR> d-------- C:\CADTool
2008-02-19 21:26 . 2008-02-26 22:30 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-19 21:26 . 2008-02-19 21:26 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-19 21:26 . 2008-02-19 21:26 <DIR> d-------- C:\Documents and Settings\Big\Application Data\SUPERAntiSpyware.com
2008-02-19 21:26 . 2008-02-19 21:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-19 21:25 . 2008-02-19 21:26 <DIR> d-------- C:\Temp\SuperAntiSpyware
2008-02-19 21:23 . 2008-02-19 21:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-19 21:21 . 2008-02-23 22:57 <DIR> d-------- C:\Temp\AVGAntiSpyware7.5
2008-02-19 07:49 . 2008-02-19 07:49 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-19 07:49 . 2008-02-19 07:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-17 19:49 . 2008-02-26 22:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-02-17 19:44 . 2008-02-17 19:45 <DIR> d-------- C:\Temp\AviraAntiVir-Free
2008-02-17 16:00 . 2008-02-23 00:27 <DIR> d-------- C:\Temp\Office2CAD
2008-02-17 15:41 . 2008-02-17 15:42 <DIR> d-------- C:\Temp\VistaDriveIcon
2008-02-10 00:15 . 2008-02-10 00:15 <DIR> d-------- C:\Program Files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-25 03:07 --------- d-----w C:\Documents and Settings\Big\Application Data\Simple Sudoku
2008-02-23 05:58 --------- d-----w C:\Program Files\SecCopy
2008-02-23 05:58 --------- d-----w C:\Program Files\QuickTime
2008-02-23 05:58 --------- d-----w C:\Program Files\dvd43
2008-02-23 05:58 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-23 05:08 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-21 18:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-18 00:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-17 22:34 --------- d-----w C:\Documents and Settings\Big\Application Data\Symantec
2008-02-17 21:58 --------- d-----w C:\Program Files\Simple Sudoku
2008-02-17 21:24 --------- d-----w C:\Program Files\MYIE2
2008-01-18 22:21 --------- d-----w C:\Documents and Settings\Marc\Application Data\Simple Sudoku
2007-12-31 23:31 --------- d-----w C:\Documents and Settings\Marc\Application Data\Autodesk
2007-12-29 04:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Autodesk
2007-12-29 03:56 --------- d-----w C:\Documents and Settings\Big\Application Data\Autodesk
2007-12-29 03:49 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2007-12-29 03:46 --------- d-----w C:\Program Files\AutoCAD MEP 2008
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2005-10-22 06:03 749348]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"@"="C:\Program Files\Internet Explorer\iexplore.exe" [2007-12-06 06:01 625664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2006-10-22 11:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-01-22 16:22 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 11:22 7700480]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-26 22:47 249896]
C:\Documents and Settings\Big\Start Menu\Programs\Startup\
Dialog Tracker.lnk - C:\Program Files\Novatix\ExplorerPlus\Nxdlghlp.exe [2003-09-08 16:26:04 65536]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a------ 2006-11-07 10:29 50736 C:\Program Files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
--a------ 2006-08-11 13:56 17920 C:\WINDOWS\CTHELPER.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
--a------ 2006-08-11 13:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\system32\drivers\si3112r.sys [2006-01-12 12:56]
R0 SiWinAcc;SiWinAcc;C:\WINDOWS\system32\drivers\SiWinAcc.sys [2004-11-01 12:21]
R3 ProtoWall;ProtoWall Network Service;C:\WINDOWS\system32\DRIVERS\ProtoWall.sys [2004-08-12 10:29]
S2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe []
S2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe []
S3 K5arddlog;K5arddlog;C:\WINDOWS\System32\rdshost.exe [2004-08-04 00:56]
S3 VICESYS;VICESYS;C:\Temp\Vice\VICESYS.sys [2004-04-19 15:27]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 22:51:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
.
**************************************************************************
.
Completion time: 2008-02-26 22:58:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-27 03:58:17
ComboFix2.txt 2008-02-23 05:53:29
.
2008-02-13 01:08:13 --- E O F ---