SDFix.exe log:
SDFix: Version 1.83
Run by Administrator - 2007-05-13 - 18:39:29.76
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hdpD9.tmp - Deleted
Removing Temp Files
ADS Check:
Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.
Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files:
---------------
Backups Folder: - C:\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes:
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\onew1ng3dEmail Removed\Sharing Folders\morrispeterson_17Email Removed\The.Number.23.[TS-Screener].[www.BitBox.us]\Thumbs.db
Finished
combofix log:
"Administrator" - 2007-05-13 18:47:09 Service Pack 2
ComboFix 07-05.13.V - Running from: "C:\Documents and Settings\Administrator\Desktop\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\death.sishen
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-13 ))))))))))))))))))))))))))))))))))
2007-05-12 15:57 <DIR> d-------- C:\DOCUME~1\ADMINI~1\DoctorWeb
2007-05-11 20:22 <DIR> d-------- C:\My Music
2007-05-11 20:21 <DIR> d-------- C:\Program Files\MP3 Convert Lord
2007-05-10 22:25 <DIR> d-------- C:\Program Files\ParadisePoker
2007-05-06 07:27 <DIR> d--hs---- C:\WINDOWS\ftpcache
2007-05-05 10:55 <DIR> d--h----- C:\WINDOWS\PIF
2007-05-04 21:08 679,936 --a------ C:\WINDOWS\system32\D3DX81ab.dll
2007-05-04 21:08 1,970,176 --a------ C:\WINDOWS\system32\d3dx9.dll
2007-05-04 21:08 <DIR> d-------- C:\Program Files\Cheat Engine
2007-04-23 16:31 <DIR> d-------- C:\Program Files\Seekmo
2007-04-21 13:21 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-04-16 22:21 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-04-16 08:00 12,245,711 --------- C:\AVG7QT.DAT
2007-04-15 20:12 162,132 --a------ C:\LSPRegBackup_15042007_201213.REG
2007-04-15 19:59 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Prevx
2007-04-15 19:58 77,312 --a------ C:\WINDOWS\ua2.dll
2007-04-15 19:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Prevx
2007-04-13 18:48 <DIR> d-------- C:\Program Files\Yahoo! Games
2007-04-13 18:48 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
2007-04-13 18:48 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\funkitron
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-13 22:49:55 -------- d-----w C:\Program Files\eMule
2007-05-13 22:49:37 -------- d-----w C:\Program Files\Steam
2007-05-12 20:38:35 -------- d-----w C:\Program Files\DAEMON Tools
2007-05-11 15:17:50 -------- d-----w C:\Program Files\Tiger Gaming
2007-05-10 20:34:06 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\U3
2007-04-30 19:34:03 -------- d-----w C:\Program Files\Conquer 2.0
2007-04-29 19:10:30 -------- d-----w C:\Program Files\Warcraft III
2007-04-20 00:04:45 79,891 ----a-w C:\WINDOWS\War3Unin.dat
2007-04-18 11:19:52 -------- d-----w C:\Program Files\BitComet
2007-04-18 11:19:31 2,560 ----a-w C:\WINDOWS\system32\BitCometRes.dll
2007-04-17 11:35:22 -------- d-----w C:\Program Files\NJStar CJK Viewer
2007-04-17 11:35:20 -------- d-----w C:\Program Files\MSN Messenger
2007-04-17 11:34:57 -------- d-----w C:\Program Files\Messenger Plus! Live
2007-04-05 01:54:53 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\CoreCodec
2007-04-05 01:54:16 -------- d-----w C:\Program Files\CoreCodec
2007-04-05 01:51:47 36,734 ----a-w C:\WINDOWS\system32\OggDSuninst.exe
2007-03-27 00:41:16 -------- d-----w C:\Program Files\Flash Movie Player
2007-03-25 04:38:55 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-03-25 04:38:55 -------- d-----w C:\Program Files\Full Tilt Poker
2007-03-25 04:30:09 -------- d-----w C:\Program Files\Incomplete
2007-03-25 04:27:21 -------- d-----w C:\Program Files\LimeWire
2007-03-25 03:57:04 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
2007-03-05 22:06:23 -------- d-----w C:\Program Files\PokerStars
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}=C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll [2007-03-29 10:31]
{55EA1964-F5E4-4D6A-B9B2-125B37655FCB}=C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll [2006-01-10 12:09]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll [2006-12-15 04:23]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-07-07 12:29]
{bf00e119-21a3-4fd1-b178-3b8537e75c92}=C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll [2006-12-11 18:46]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe"
"igfxpers"="C:\\WINDOWS\\system32\\igfxpers.exe"
"High Definition Audio Property Page Shortcut"="HDAShCut.exe"
"SoundMan"="SOUNDMAN.EXE"
"AlcWzrd"="ALCWZRD.EXE"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"PrevxOne"="\"C:\\Program Files\\Prevx1\\PXConsole.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 C:\WINDOWS\system32\HdAShCut.exe])
"SoundMan"="SOUNDMAN.EXE" [])
"AlcWzrd"="ALCWZRD.EXE" [])
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 04:23]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-09-27 19:11]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-09-26 10:49]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-09-14 16:09]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-04-24 09:10]
"PrevxOne"="C:\Program Files\Prevx1\PXConsole.exe" [2007-03-27 11:16]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2006-07-29 19:34]
"Steam"="c:\program files\steam\steam.exe" [2007-01-08 19:25]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2006-09-14 10:15]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"Steam"="\"c:\\program files\\steam\\steam.exe\" -silent"
"eMuleAutoStart"="C:\\Program Files\\eMule\\emule.exe -AutoStart"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoVisualStyleChoice"=dword:00000000
"NoColorChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRemoteRecursiveEvents"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"=dword:00000001
"NoSaveSettings"=dword:00000000
"NoSMConfigurePrograms"=dword:00000001
"NoRecentDocsMenu"=dword:00000001
"NoLowDiskSpaceChecks"=dword:00000001
"NoChangeKeyboardNavigationIndicators"=dword:00000000
"NoSharedDocuments"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0
Security Packages kerberosmsv1_0schannelwdigest
Notification Packages scecli
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter HTTPFilter
LocalService AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV
NetworkService DnsCache
DcomLaunch DcomLaunchTermService
rpcss RpcSs
imgsvc StiSvc
termsvcs TermService
Usnsvc usnsvc
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{732da908-4d50-11db-a548-00112f2f07c9}]
Shell\AutoRun\command M:\LaunchU3.exe
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20070512-155154-898
O2 - BHO: Seekmo Search Assistant Helper /fleok=1D8A83A5C4E5147C9EAB6D2A1FBB39BFE4976E26CAEDDA7D5474452C3FCEC3 - {5929CD6E-2062-44a4-B2C5-2C7E78FBAB38} - c:\program files\seekmo\seekmohook.dll (file missing)
backup-20070512-155154-753
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
backup-20070512-155154-533
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
backup-20070512-155154-928
O4 - HKCU\..\Run: [udz7e3iqlkel] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Servere.exe
backup-20070510-155113-807
O4 - HKLM\..\RunOnce: [SeekmoToolbar] cmd /c "rmdir "C:\Program Files\SeekmoToolbar" /s /q"
backup-20070510-155027-371
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
backup-20070510-155015-765
O4 - HKLM\..\Run: [seekmo] "c:\program files\seekmo\seekmo.exe"
backup-20070510-155015-910
O4 - HKLM\..\Run: [msccrt] C:\WINDOWS\msccrt.exe
backup-20070510-152700-110
O3 - Toolbar: Seekmo Toolbar - {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - C:\Program Files\SeekmoToolbar\Bin\4.8.4.0\SkHostIE.dll
backup-20070510-152700-965
O3 - Toolbar: Starware Recipe Toolbar - {D49E9D35-254C-4c6a-9D17-95018D228FF5} - C:\Program Files\Starware337\bin\Starware337.dll
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-05-13 18:50:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 2007-05-13 18:51:08 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-13 18:51
And after that, prevx found a malware called swsc.exe