Hi,
I've been trying to remove a stubborn infection in the MBR on a pc. The OS is Windows XP Home, SP2. I've tried running Gmer and mbr.exe with no success. The mbr log as follows:
Stealth MBR rootkit detector 0.2.4 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
malicious code @ sector 0x4c50135 size 0x1fd !
copy of MBR has been found in sector 62 !
I've tried the following in both normal mode and safe modes, where possible:
- run Eset Smart Security and Malwarebytes scans and nothing detected
- fixmbr in recovery console
- Combofix
- SDFix
- NOD32 DOS scan
ComboFix log:
ComboFix 08-09-28.03 - Lynette 2008-09-30 10:42:33.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.
75 [GMT 10:00]
Running from: C:\Documents and Settings\Lynette\Desktop\C
omboFix\Co
mboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((
((((((((((
((( Other Deletions ))))))))))))))))))))))))))
))))))))))
))))))))))
)))
.
C:\WINDOWS\dcstds3.dll
.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-30 ))))))))))))))))))))))))))
)))))
.
2008-09-30 09:20 . 2008-09-30 09:20 <DIR> d-------- C:\Program Files\ESET
2008-09-30 09:04 . 2008-09-30 08:35 66,048 --a------ C:\mbr.exe
2008-09-30 08:35 . 2008-09-30 10:17 250 --a------ C:\WINDOWS\gmer.ini
2008-09-29 21:47 . 2008-09-30 09:08 <DIR> d-------- C:\Program Files\TDS3
2008-09-29 20:39 . 2008-09-30 10:42 <DIR> d-------- C:\WINDOWS\system32\NtmsDa
ta
2008-09-29 20:20 . 2008-09-29 20:22 5,251,072 --a------ C:\WINDOWS\sectest.db
2008-09-29 19:49 . 2008-09-29 19:49 <DIR> d-------- C:\Documents and Settings\Administrator\App
lication Data\SUPERAntiSpyware.com
2008-09-29 19:49 . 2008-09-29 19:49 <DIR> d-------- C:\Documents and Settings\Administrator
2008-09-29 19:21 . 2008-09-30 09:27 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-29 19:21 . 2008-09-29 19:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-29 18:09 . 2008-09-29 18:09 <DIR> d-------- C:\Program Files\PrevxCSI
2008-09-29 18:09 . 2008-09-30 09:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-09-29 18:09 . 2008-09-29 18:09 17,408 --a------ C:\WINDOWS\system32\driver
s\pxark.sy
s
2008-09-29 17:02 . 2008-09-29 17:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-29 15:57 . 2006-05-25 15:52 162,304 --a------ C:\WINDOWS\system32\ztvunr
ar36.dll
2008-09-29 15:57 . 2003-02-02 20:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3
.dll
2008-09-29 15:57 . 2005-08-26 01:50 77,312 --a------ C:\WINDOWS\system32\ztvuna
ce26.dll
2008-09-29 15:57 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\system32\unacev
2.dll
2008-09-29 15:57 . 2006-06-19 13:01 69,632 --a------ C:\WINDOWS\system32\ztvcab
inet.dll
2008-09-29 15:56 . 2008-09-30 09:14 <DIR> d-------- C:\Program Files\Trojan Remover
2008-09-29 15:26 . 2008-09-29 15:26 <DIR> d-------- C:\Documents and Settings\Lynette\Applicati
on Data\ESET
2008-09-29 15:01 . 2008-09-29 15:01 <DIR> d-------- C:\WINDOWS\ERUNT
2008-09-29 14:59 . 2008-09-29 14:59 2,740 --a------ C:\WINDOWS\system32\tmp.re
g
2008-09-29 14:58 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSI
D.exe
2008-09-29 14:58 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchST
S.exe
2008-09-29 14:58 . 2008-09-08 23:38 88,576 --a------ C:\WINDOWS\system32\AntiXP
VSTFix.exe
2008-09-29 14:58 . 2008-09-02 16:51 86,528 --a------ C:\WINDOWS\system32\VACFix
.exe
2008-09-29 14:58 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix
.exe
2008-09-29 14:58 . 2008-08-28 22:36 82,432 --a------ C:\WINDOWS\system32\IEDFix
.C.exe
2008-09-29 14:58 . 2008-08-18 12:19 82,432 --a------ C:\WINDOWS\system32\404Fix
.exe
2008-09-29 14:58 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Proces
s.exe
2008-09-29 14:58 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphi
ve.exe
2008-09-29 14:58 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix
.exe.vir
2008-09-29 14:17 . 2008-09-29 14:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-09-29 11:38 . 2008-09-29 11:38 <DIR> d-------- C:\Documents and Settings\Lynette\Applicati
on Data\Malwarebytes
2008-09-29 11:37 . 2008-09-29 11:38 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-29 11:37 . 2008-09-29 11:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-29 11:37 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\driver
s\mbamswis
sarmy.sys
2008-09-29 11:37 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\driver
s\mbam.sys
.
((((((((((((((((((((((((((
((((((((((
(((( Find3M Report ))))))))))))))))))))))))))
))))))))))
))))))))))
))))))
.
2008-09-29 02:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-17 03:08 --------- d-----w C:\Documents and Settings\Lynette\Applicati
on Data\MSN6
2008-09-02 02:34 --------- d-----w C:\Documents and Settings\Lynette\Applicati
on Data\U3
2008-08-22 23:26 --------- d-----w C:\Documents and Settings\Lynette\Applicati
on Data\AdobeUM
2008-07-18 12:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dl
l
2008-07-18 12:10 53,448 ----a-w C:\WINDOWS\system32\wuaucl
t.exe
2008-07-18 12:10 45,768 ----a-w C:\WINDOWS\system32\wups2.
dll
2008-07-18 12:10 36,552 ----a-w C:\WINDOWS\system32\wups.d
ll
2008-07-18 12:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.
dll
2008-07-18 12:09 325,832 ----a-w C:\WINDOWS\system32\wucltu
i.dll
2008-07-18 12:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.
dll
2008-07-18 12:09 1,811,656 ----a-w C:\WINDOWS\system32\wuauen
g.dll
2008-07-18 12:07 270,880 ----a-w C:\WINDOWS\system32\mucltu
i.dll
2008-07-18 12:07 210,976 ----a-w C:\WINDOWS\system32\muweb.
dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.
dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\winine
t.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsoc
k.dll
2006-12-11 01:56 21,408 ----a-w C:\Documents and Settings\Lynette\Applicati
on Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((
((( snapshot@2008-09-29_19.00.
54.07 ))))))))))))))))))))))))))
))))))))))
)))))
.
+ 2008-09-29 23:44:43 884,736 ----a-w C:\WINDOWS\gmer.dll
+ 2008-09-29 23:44:37 811,008 ----a-w C:\WINDOWS\gmer.exe
+ 2007-03-06 01:22:39 213,216 -c----w C:\WINDOWS\ie7updates\KB93
8127-v2-IE
7\spuninst
\spuninst.
exe
+ 2007-03-06 01:23:47 371,424 -c----w C:\WINDOWS\ie7updates\KB93
8127-v2-IE
7\spuninst
\updspapi.
dll
+ 2007-07-12 23:31:54 765,952 -c----w C:\WINDOWS\ie7updates\KB93
8127-v2-IE
7\vgx.dll
+ 2008-09-29 11:29:41 10,134 ----a-r C:\WINDOWS\Installer\{FBF0
9842-EB7F-
4BC2-BD32-
DDE2572B21
95}\callms
i.exe
+ 2008-09-29 11:29:41 140,544 ----a-r C:\WINDOWS\Installer\{FBF0
9842-EB7F-
4BC2-BD32-
DDE2572B21
95}\egui.e
xe
- 2007-08-13 08:54:10 765,952 -c--a-w C:\WINDOWS\system32\dllcac
he\VGX.dll
+ 2008-05-27 17:23:58 765,952 -c--a-w C:\WINDOWS\system32\dllcac
he\vgx.dll
+ 2008-06-30 22:56:22 39,944 ----a-w C:\WINDOWS\system32\driver
s\eamon.sy
s
+ 2008-06-30 23:04:34 71,688 ----a-w C:\WINDOWS\system32\driver
s\epfw.sys
+ 2008-06-30 23:04:38 54,280 ----a-w C:\WINDOWS\system32\driver
s\epfwtdi.
sys
+ 2008-09-29 23:44:43 85,969 ----a-w C:\WINDOWS\system32\driver
s\gmer.sys
- 2008-09-29 03:49:22 125,320 ----a-w C:\WINDOWS\system32\FNTCAC
HE.DAT
+ 2008-09-29 10:38:54 125,320 ----a-w C:\WINDOWS\system32\FNTCAC
HE.DAT
+ 2003-06-11 08:05:07 32,768 ----a-w C:\WINDOWS\system32\tds3sh
l.dll
+ 1999-01-12 05:19:12 195,584 ----a-w C:\WINDOWS\system32\xvoice
.dll
.
((((((((((((((((((((((((((
((((((((((
( Reg Loading Points ))))))))))))))))))))))))))
))))))))))
))))))))))
))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
E\Microsof
t\Windows\
CurrentVer
sion\Run]
"ctfmon.exe"="C:\WINDOWS\s
ystem32\ct
fmon.exe" [2004-08-04 15360]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
[HKEY_LOCAL_MACHINE\SOFTWA
RE\Microso
ft\Windows
\CurrentVe
rsion\Run]
"iTunesHelper"="C:\Program
Files\iTunes\iTunesHelper.
exe" [2006-02-23 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe
" [2006-05-03 155648]
"NvCplDaemon"="C:\WINDOWS\
system32\N
vCpl.dll" [2004-10-29 4620288]
"NvMediaCenter"="C:\WINDOW
S\system32
\NvMcTray.
dll" [2004-10-29 86016]
"SunJavaUpdateSched"="C:\P
rogram Files\Java\jre1.5.0_09\bin
\jusched.e
xe" [2006-10-12 49263]
"PCSuiteTrayApplication"="
C:\Program
Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-06-15 229376]
"SSBkgdUpdate"="C:\Program
Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgd
update.exe
" [2006-09-28 185896]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4
.0\OpwareS
E4.exe" [2006-10-11 75304]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-07-01 1447168]
"SoundMan"="SOUNDMAN.EXE" [2004-07-01 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2004-10-29 C:\WINDOWS\system32\nwiz.e
xe]
[HKEY_USERS\.DEFAULT\Softw
are\Micros
oft\Window
s\CurrentV
ersion\Run
]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaD
etector.ex
e" [2007-09-28 443968]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
[2006-06-07 180224]
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Ko
dak Software Updater.exe [2004-02-13 16423]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
standardpr
ofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
standardpr
ofile\Auth
orizedAppl
ications\L
ist]
"%windir%\\system32\\sessm
gr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.e
xe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.
exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\
\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.e
xe"=
"C:\\Program Files\\iTunes\\iTunes.exe"
=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
=
"C:\\Program Files\\Bonjour\\mDNSRespon
der.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.e
xe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.
exe"=
R0 pxark;pxark;C:\WINDOWS\sys
tem32\driv
ers\pxark.
sys [2008-09-29 17408]
R2 CSIScanner;CSIScanner;C:\P
rogram Files\PrevxCSI\prevxcsi.ex
e [2008-09-29 618040]
S3 KLSIENET;Driver for USB Ethernet Adapter;C:\WINDOWS\system3
2\DRIVERS\
usb101et.s
ys [2004-08-03 32384]
S3 STAC97NA;SigmaTel 3D Environmental Audio;C:\WINDOWS\system32\
drivers\st
ac97na.sys
[2002-09-20 296179]
S3 STAC97NH;STAC97NH;C:\WINDO
WS\system3
2\drivers\
stac97nh.s
ys [2002-09-20 231983]
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\explo
rer\mountp
oints2\{09
af1e79-0b4
2-11dc-8bd
a-000129fd
70fc}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
.
------- Supplementary Scan -------
.
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O18 -: Handler: ms-its51 - {F6F1E82D-DE4D-11D2-875C-0
000F810575
4} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\itss51.dll
O16 -: DirectAnimation Java Classes - file://C:\WINDOWS\Java\cla
sses\dajav
a.cab
C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\cla
sses\xmlds
o.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************
**********
**********
**********
**********
********
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-30 10:46:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
**********
**********
**********
**********
********
.
Completion time: 2008-09-30 10:55:39
ComboFix-quarantined-files
.txt 2008-09-30 00:55:14
ComboFix2.txt 2008-09-29 09:01:48
Pre-Run: 4,947,554,304 bytes free
Post-Run: 5,022,281,728 bytes free
169 --- E O F --- 2008-09-29 17:02:51
--------------------------
----------
----------
----------
----------
----------
----------
----------
----------
----------
-----
Is there any way to kill this thing without performing a clean reinstall.
Regards
Chiarne