I have now been over a week trying to get my computer to run properly. The bottom of this post contains the latest log file. I am using a SOny Vaio laptop with Windows XP SP2 which became infected with a variant of the zlob virus. I used Trend Micro PCCillin to remove the virus and have deleted the files relating to the virus together with the restore points affected as reported by Trend Micor. I am not sure which variant it was as I have deleted the information in trying to get the machine running. I am not sure why the virus got past PCCIllin in the first place.
The issue is now that in a normal boot situation windows loads but no programme
will load including explorer, cannot install anything, cannot access any of the management consoles or really do anything - each time I try I get an error saying I may not have permission to access the file. My login is as a computer administrator - I have rechecked that that has not changed and I managed to verify from within normall Windows. I also found out that sometimes during the boot procedure if I click immediately the icons appear then I can open certain programmes but a few seconds later the same programme will not open giving the permissions error again.
I assumed that the infection had somehow changed the permissions on my system so I booted into safe mode and ran Dial-a-fix reset permissions, reset registry associations etc. which completed OK saying only some components could not be found. I rebooted normally but the same symptoms existed. I figured that something must be loading during the boot process to refuse my access but in mnanaging to get into the computer management console one time during boot up I found that I am still listed in the Administrators group and a new account I set up with administrator rights also exhibited the same symptoms. So I figured maybe something was loading and unloading into the registry to disguise itself when you boot into safe mode somehow. I removed the HKLM run and HKCU run keys from the registry together with all the startup programs in D&S/... Startup folder for All Users and my own profile and rebooted - same problem - no access allowed. I reinstated these back again and still cannot acccess any programmes but now do not even seem to be able to get into anything during Windows startup anymore.
I can run Trend Micro in normal mode for some reason this does not seem to be prevented from loading but I am not sure why. Have run a scan with that several times and also using House call which does not produce any infections or problems. I cannot run the programmes listed in the 5 step process so am not sure what to do now. This all started from the zlob infection which came packaged in a bad video codec.
Please help if you can and thanks for your time reading this.
Ian
I have Bart disk so have been able to restore the system to a previous point long before the virus infected the machine but that did not solve things.
*** Since posting this message and following logs I managed eventually (very eventually) to get a ComboFix to run and here is the logfile - immediately after running combofix the programs on the computer are accessible but after shutting down and restarting the computer the programs are again unavailable. Nothing will run - I cannot view text files, cannot access control panel items, cannot run cmd, cannot open any .bat, .exe and so on. The computer is unusable - any time any of the above programs are attempted to be opened I get a 'You may not have the appropriate permissions...' warning. I have again run repair permissions and repair associations from Dial a Fix in safe mode but to no avail. The first time after running these programs the icons take a very long time to appear on reboot - looks like maybe the virus hijack's the computer at startup and disables everything from running. For some reason about 1 time in 10 you can very quickly double click an icon immediately it appears and get it to run but the other 9 times it doesn;t matter how quick you are it just locks me out.
P.S. Tried to install Recovery Console but cannot because virus refuses access - Anyway have Bart PE disk so can use that for most repair things. Log:
ComboFix 08-07-09.4 - Ian 2008-07-10 6:41:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.477 [GMT -4:00]
Running from: C:\Documents and Settings\Ian\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\setup.exe
C:\WINDOWS\system32\oeminfo.ini
.
((((((((((((((((((((((((( Files Created from 2008-06-10 to 2008-07-10 )))))))))))))))))))))))))))))))
.
2008-07-10 03:27 . 2008-07-10 03:27 <DIR> d-------- C:\WINDOWS\system32\788877
2008-07-09 21:15 . 2008-07-10 03:27 <DIR> d-------- C:\WINDOWS\SQLTools9_KB948109_ENU
2008-07-09 21:11 . 2008-07-10 03:27 <DIR> d-------- C:\WINDOWS\SQL9_KB948109_ENU
2008-07-09 11:59 . 2008-07-09 11:59 <DIR> d-------- C:\Documents and Settings\Ian\Application Data\Malwarebytes
2008-07-09 11:59 . 2008-07-09 11:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-09 11:58 . 2008-07-10 03:27 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-09 10:24 . 2008-07-10 03:55 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-07-09 10:24 . 2008-07-09 10:24 <DIR> d-------- C:\Documents and Settings\Ian\Application Data\SUPERAntiSpyware.com
2008-07-09 10:18 . 2008-07-10 06:13 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-09 05:47 . 2008-07-09 05:47 <DIR> d-------- C:\Deckard
2008-07-07 07:07 . 2008-07-09 21:08 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-07-07 06:42 . 2008-07-10 02:25 3,153,920 --a------ C:\WINDOWS\sectest.db
2008-07-06 19:52 . 2008-07-06 19:52 <DIR> d-------- C:\WINDOWS\Recent
2008-07-06 19:52 . 2008-07-06 19:52 <DIR> d-------- C:\WINDOWS\Cookies
2008-07-05 00:56 . 2008-07-10 06:09 12 --a------ C:\WINDOWS\bthservsdp.dat
2008-07-04 07:31 . 2004-08-14 01:06 <DIR> d-------- C:\Documents and Settings\Test\Application Data\Symantec
2008-07-04 07:31 . 2008-07-07 09:04 <DIR> d-------- C:\Documents and Settings\Test\Application Data\Sony Corporation
2008-07-04 07:31 . 2008-07-06 19:52 <DIR> d-------- C:\Documents and Settings\Test
2008-07-04 07:30 . 2004-08-14 01:06 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Symantec
2008-07-04 07:30 . 2004-08-14 00:50 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Sony Corporation
2008-07-04 07:30 . 2008-07-06 19:52 <DIR> d-------- C:\Documents and Settings\Guest
2008-06-30 04:30 . 2008-07-08 05:47 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-06-30 01:46 . 2008-06-30 01:46 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-06-30 01:26 . 2008-06-30 01:26 3,153,920 --a------ C:\secsetup.sdb
2008-06-30 01:22 . 2008-06-30 01:17 379,392 --a------ C:\subinacl.msi
2008-06-30 01:15 . 2008-06-29 21:08 528 --a------ C:\reset.cmd
2008-06-29 10:38 . 2008-06-29 10:38 <DIR> d-------- C:\WINDOWS\system32\HouseCall 6.6
2008-06-29 10:38 . 2008-07-10 03:46 <DIR> d-------- C:\Documents and Settings\Ian\Application Data\HouseCall 6.6
2008-06-29 09:55 . 2008-06-29 09:55 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-06-11 05:33 . 2008-06-13 09:10 272,128 --a--c--- C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-10 10:13 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-10 07:45 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-07-10 01:16 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-27 16:01 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-27 15:58 --------- d-----w C:\Documents and Settings\Ian\Application Data\AdobeUM
2008-05-14 02:09 --------- d-----w C:\Program Files\HandicapMaster7
2008-05-14 02:09 --------- d-----w C:\Documents and Settings\Ian\Application Data\HandicapMaster7
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2007-09-17 02:12 2,994 ----a-w C:\Documents and Settings\Ian\Application Data\SAS7_000.DAT
2006-06-28 10:14 1,508 ----a-w C:\Documents and Settings\Ian\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-03 17:42 401491]
"E06AXLRD_6516159"="C:\Program Files\Microsoft Encarta\Encarta Premium DVD 2006\EDICT.EXE" [2005-06-03 13:30 301776]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"OE"="C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" [2006-09-26 23:37 315392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2003-11-07 21:21 114688]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-26 00:00 335872]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [2004-06-30 00:45 180224]
"HKSERV.EXE"="C:\Program Files\Sony\HotKey Utility\HKserv.exe" [2004-06-29 17:49 122880]
"Switcher.exe"="C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2004-08-03 19:56 294912]
"VAIO Update 2"="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" [2004-01-17 06:36 135168]
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 01:08 28672]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2003-06-30 21:56 188416]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2003-06-30 22:00 65536]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 16:00 155648]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 16:15 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 16:15 81920]
"CnxDslTaskBar"="C:\Program Files\Conexant\ADSL\AccessRunner ADSL\CnxDslTb.exe" [2004-04-27 13:00 466944]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 08:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 08:00 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 08:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 08:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 08:00 455168]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2006-09-29 22:02 3112960]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36 256576]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.EXE" [2007-03-06 06:11 3364616]
"AirCardEnabler"="C:\Program Files\Sierra Wireless\Network Adapter Manager\Network Adapter Manager.exe" [2006-10-26 09:37 180224]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 08:00 110592 C:\WINDOWS\system32\bthprops.cpl]
C:\Documents and Settings\Ian\Start Menu\Programs\Startup\
Check for TWS Updates.lnk - C:\Jts\WiseUpdt.exe [2006-08-10 03:21:05 194775]
Dragon NaturallySpeaking.lnk - C:\Program Files\Nuance\NaturallySpeaking9\Program\natspeak.exe [2006-12-11 17:20:40 2332264]
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe [2008-05-13 21:20:46 474808]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
Belkin Wireless Networking Utility.lnk - C:\Program Files\Belkin\F5D8011v2\Belkinwcui.exe [2007-06-01 09:31:40 1576960]
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2005-10-12 23:00:30 1048576]
eFax DllCmd 4.0.lnk - C:\Program Files\eFax Messenger 4.0\J2GDllCmd.exe [2005-12-19 11:22:07 107008]
eFax Tray Menu 4.0.lnk - C:\Program Files\eFax Messenger 4.0\J2GTray.exe [2005-12-19 11:22:08 500224]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-11-04 16:04:48 176128]
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 15:12:08 16423]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
"MSACM.CEGSM"= mobilev.acm
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"=
"C:\\CyberTrader\\CyberTraderPro.exe"=
"C:\\Program Files\\eSignal\\winros.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Tee2Green\\SureAnalysis\\SureAnalysis.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\DAP\\DAP.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 sbp2port;SBP-2 Transport/Protocol Bus Driver;C:\WINDOWS\system32\DRIVERS\sbp2port.sys [2004-08-03 23:59]
R1 DcCam;Kodak Camera Proxy;C:\WINDOWS\system32\DRIVERS\DcCam.sys [2005-06-16 15:41]
R1 DMICall;Sony DMI Call service;C:\WINDOWS\system32\DRIVERS\DMICall.sys [2000-12-05 19:18]
R1 tmtdi;Trend Micro TDI Driver;C:\WINDOWS\system32\DRIVERS\tmtdi.sys [2006-09-14 21:28]
R2 BlueSoleil Hid Service;BlueSoleil Hid Service;C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe [2005-01-27 03:28]
R2 BthServ;Bluetooth Support Service;C:\WINDOWS\system32\svchost.exe [2004-08-04 08:00]
R2 DCFS2K;Kodak DCFS2K Driver;C:\WINDOWS\system32\drivers\dcfs2k.sys [2005-03-31 08:47]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service;C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2006-07-02 21:42]
R2 s24trans;WLAN Transport;C:\WINDOWS\system32\DRIVERS\s24trans.sys [2006-07-02 23:16]
R2 SQLBrowser;SQL Server Browser;c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2007-02-10 05:29]
R2 SQLWriter;SQL Server VSS Writer;c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2007-02-10 05:29]
R2 SwiWiFiComm;SwiWiFiComm;C:\Program Files\Sierra Wireless\AirCard 580\Generic\Components\swiwificomm.exe [2006-10-26 09:38]
R2 tmmbd;Trend Micro MBD Driver;C:\WINDOWS\system32\DRIVERS\tm_mbd_c.sys [2006-09-14 21:28]
R2 Tmpreflt;Tmpreflt;C:\WINDOWS\system32\drivers\Tmpreflt.sys [2008-05-02 16:21]
R2 tmxpflt;tmxpflt;C:\WINDOWS\system32\drivers\TmXPFlt.sys [2008-05-02 16:22]
R2 Vsapint;Vsapint;C:\WINDOWS\system32\drivers\VsapiNT.sys [2008-05-02 16:17]
R3 aeaudio;aeaudio;C:\WINDOWS\system32\drivers\aeaudio.sys [2003-03-13 21:34]
R3 ApfiltrService;Alps Pointing-device Filter Driver;C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2003-09-29 17:31]
R3 apusbsnt;Sierra Wireless USB Modem Device Driver;C:\WINDOWS\system32\DRIVERS\apusbsnt.sys [2003-12-09 15:52]
R3 E100B;Intel® PRO Adapter Driver;C:\WINDOWS\system32\DRIVERS\e100b325.sys [2003-09-17 15:44]
R3 HSFHWICH;HSFHWICH;C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys [2003-10-14 20:08]
R3 smwdm;smwdm;C:\WINDOWS\system32\drivers\smwdm.sys [2003-03-17 13:46]
R3 SNC;Sony Notebook Control Device;C:\WINDOWS\system32\Drivers\SonyNC.sys [2000-11-09 23:15]
R3 SPI;Sony Programmable I/O Control Device;C:\WINDOWS\system32\DRIVERS\SonyPI.sys [2002-08-20 15:59]
R3 tifmsony;tifmsony;C:\WINDOWS\system32\drivers\tifmsony.sys [2004-05-21 16:46]
R3 tmcfw;Trend Micro Common Firewall Service;C:\WINDOWS\system32\DRIVERS\TM_CFW.sys [2006-08-24 22:58]
R3 w29n51;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows XP;C:\WINDOWS\system32\DRIVERS\w29n51.sys [2006-06-29 19:49]
S1 Exportit;Exportit;C:\WINDOWS\system32\DRIVERS\exportit.sys [2005-03-31 09:00]
S2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS);c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe [2007-02-10 05:29]
S2 MSSQL$VPINSTANCE;SQL Server (VPINSTANCE);c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2007-02-10 05:29]
S2 PcCtlCom;Trend Micro Central Control Component;C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe [2006-09-29 21:34]
S2 Tmntsrv;Trend Micro Real-time Service;C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe [2006-09-29 21:38]
S2 TmPfw;Trend Micro Personal Firewall;C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe [2006-09-14 21:31]
S2 tmproxy;Trend Micro Proxy Service;C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe [2006-09-14 21:34]
S3 Airgo;Belkin Wireless Pre-N Notebook Network Driver;C:\WINDOWS\system32\DRIVERS\wnihdd51.sys [2004-10-25 04:10]
S3 AWINDIS5;AWINDIS5 Protocol Driver;C:\WINDOWS\system32\AWINDIS5.SYS [2002-04-11 20:43]
S3 BthEnum;Bluetooth Request Block Driver;C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2004-08-04 02:10]
S3 BthPan;Bluetooth Device (Personal Area Network);C:\WINDOWS\system32\DRIVERS\bthpan.sys [2004-08-04 01:58]
S3 BTHPORT;Bluetooth Port Driver;C:\WINDOWS\system32\Drivers\BTHport.sys [2008-06-13 09:10]
S3 BTHUSB;Bluetooth Radio USB Driver;C:\WINDOWS\system32\Drivers\BTHUSB.sys [2004-08-04 02:10]
S3 CnxEtP;AccessRunner USB ADSL WAN Adapter Filter Driver;C:\WINDOWS\system32\DRIVERS\CnxEtP.sys [2003-09-12 10:26]
S3 CnxEtU;AccessRunner USB ADSL Interface Device Driver;C:\WINDOWS\system32\DRIVERS\CnxEtU.sys [2003-09-12 10:26]
S3 CnxTgN;AccessRunner USB ADSL WAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\CnxTgN.sys [2003-10-29 15:02]
S3 DcFpoint;DcFpoint;C:\WINDOWS\system32\DRIVERS\DcFpoint.sys [2005-03-31 08:47]
S3 DcLps;Legacy Polling Service;C:\WINDOWS\system32\DRIVERS\DcLps.sys [2005-03-31 08:47]
S3 DcPTP;dcptp;C:\WINDOWS\system32\DRIVERS\DcPTP.sys [2005-03-31 08:47]
S3 grmnusb;grmnusb;C:\WINDOWS\system32\drivers\grmnusb.sys [2005-11-07 17:17]
S3 LEX_AS_NIC_SERVICE_YNOS;LAN-Express AS IEEE 802.11g Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\ExpasAG.sys [2004-07-07 18:12]
S3 MSCSPTISRV;MSCSPTISRV;C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [2006-04-27 17:35]
S3 NdisIP;Microsoft TV/Video Connection;C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 12:10]
S3 NETMW145;Belkin N1 Wireless Notebook Card Service for Windows XP;C:\WINDOWS\system32\DRIVERS\NETMW145.sys [2006-08-16 14:43]
S3 PACSPTISVR;PACSPTISVR;C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [2006-04-27 17:27]
S3 PhilCam8116;Logitech QuickCam Pro 3000(PID_08B0);C:\WINDOWS\system32\DRIVERS\CamDrL21.sys [2002-12-10 06:53]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI);C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2004-08-04 02:10]
S3 slabbus;sureshotgps USB Device driver (WDM);C:\WINDOWS\system32\DRIVERS\slabbus.sys [2006-03-07 20:28]
S3 slabser;sureshotgps USB-UART Drivers;C:\WINDOWS\system32\DRIVERS\slabser.sys [2006-03-07 20:28]
S3 SLIP;BDA Slip De-Framer;C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 12:10]
S3 SPTISRV;Sony SPTI Service;C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe [2006-04-27 17:16]
S3 SSScsiSV;SonicStage SCSI Service;C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe [2006-05-08 04:24]
S3 TVICHW32;TVICHW32;C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS [2006-08-08 11:26]
S3 w22n51;Intel® PRO/Wireless 2200 Adapter Driver;C:\WINDOWS\system32\DRIVERS\w22n51.sys []
S3 wceusbsh;Windows CE USB Serial Host Driver;C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2003-12-22 13:28]
S3 WNIPROT5;WNIPROT5 Protocol Driver;C:\WINDOWS\System32\WNIPROT5.SYS []
S4 MSSQLServerADHelper;SQL Server Active Directory Helper;c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2005-10-14 04:50]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da713c10-a451-11da-8435-0011502a3b0a}]
\Shell\AutoRun\command - D:\setupSNK.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-06-28 00:14:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2005-08-22 11:40:09 C:\WINDOWS\Tasks\Registration reminder 2.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
- - - - ORPHANS REMOVED - - - -
ShellIconOverlayIdentifiers-{E4000AC4-5E5F-4956-807A-C5854405D64F} - %SystemRoot%\system32\VirtualExpander\VEShellExt.dll
HKLM-Run-Mouse Suite 98 Daemon - ICO.EXE
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-10 06:43:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Completion time: 2008-07-10 6:51:29
ComboFix-quarantined-files.txt 2008-07-10 10:51:26
Pre-Run: 10,613,420,032 bytes free
Post-Run: 10,578,808,832 bytes free
234 --- E O F --- 2008-06-21 07:08:56
Edited by slipperx, 11 July 2008 - 08:13 AM.