and here is the combofix log:
ComboFix 07-11-07.3 - Owner 2007-11-12 13:06:44.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.144 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\orqss.ini
C:\WINDOWS\system32\ssqro.dll
.
((((((((((((((((((((((((( Files Created from 2007-10-12 to 2007-11-12 )))))))))))))))))))))))))))))))
.
2007-11-07 09:43 82,061 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-11-07 09:43 81,549 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-11-07 09:42 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-11-07 09:42 8,712,736 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-11-07 09:42 35,872 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-11-07 09:41 <DIR> d-------- C:\KAV
2007-11-07 01:36 79,936 --a------ C:\WINDOWS\system32\sidrynms.dll
2007-11-07 01:33 86,080 --a------ C:\WINDOWS\system32\ycavvtap.dll
2007-11-07 01:27 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-07 01:22 79,936 --a------ C:\WINDOWS\system32\xhrmaqlk.dll
2007-11-07 01:20 <DIR> d-------- C:\VundoFix Backups
2007-11-07 01:19 86,080 --a------ C:\WINDOWS\system32\iqslfnve.dll
2007-11-07 00:12 79,936 --a------ C:\WINDOWS\system32\urbpyjdq.dll
2007-11-06 22:13 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-11-06 22:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-06 22:03 81,472 --a------ C:\WINDOWS\system32\nrqhktuw.dll
2007-11-06 21:10 81,472 --a------ C:\WINDOWS\system32\ahargfis.dll
2007-11-06 21:07 87,104 --a------ C:\WINDOWS\system32\vheyocon.dll
2007-11-06 19:39 81,472 --a------ C:\WINDOWS\system32\tswihdmj.dll
2007-11-06 19:17 81,472 --a------ C:\WINDOWS\system32\kibpwowx.dll
2007-11-06 18:21 164 --a------ C:\install.dat
2007-11-06 18:20 81,472 --a------ C:\WINDOWS\system32\mnpeojmi.dll
2007-11-06 18:06 1,508 --a------ C:\WINDOWS\system32\tmp.reg
2007-11-06 17:59 81,472 --a------ C:\WINDOWS\system32\uoxbkwbc.dll
2007-11-06 17:53 71,232 --a------ C:\WINDOWS\system32\ygnsemyh.exe
2007-11-06 13:53 81,472 --a------ C:\WINDOWS\system32\vxenlsyv.dll
2007-11-06 13:44 145,984 --a------ C:\WINDOWS\system32\gclprlsu.dll
2007-11-05 13:52 83,008 --a------ C:\WINDOWS\system32\pugkptxf.dll
2007-11-05 01:35 36,352 --a------ C:\WINDOWS\system32\byxvvts.dll
2007-10-30 08:43 <DIR> d-------- C:\WINDOWS\system32\Mz02r
2007-10-30 08:43 <DIR> d-------- C:\Temp\mZOr
2007-10-22 03:08 16,358 --a------ C:\WINDOWS\system32\instdump.zip
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-12 18:23 4,412 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2007-11-12 18:23 117,428 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-12 04:05 --------- d-----w C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2007-11-12 01:37 --------- d-----w C:\Program Files\Lx_cats
2007-11-07 19:40 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-07 19:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-07 06:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-07 04:57 --------- d-----w C:\Program Files\Common Files\Real
2007-11-06 04:27 --------- d-----w C:\Documents and Settings\Owner\Application Data\U3
2007-10-22 08:19 --------- d-----w C:\Program Files\GRAPE GBW32 v4.0
2007-10-22 08:18 --------- d-----w C:\Program Files\BitTorrent
2007-10-04 23:44 --------- d-----w C:\Program Files\iTunes
2007-10-04 23:43 --------- d-----w C:\Program Files\iPod
2007-09-26 02:12 --------- d-----w C:\Documents and Settings\Owner\Application Data\Promethean
2007-09-19 12:41 --------- d-----w C:\Program Files\Apple Software Update
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-02-28 04:09 6,800 ----a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((( snapshot_2007-11-07_18.32.22.65 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-07 14:23:03 1,257,472 ----a-w C:\WINDOWS\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2007-11-08 22:03:56 1,265,664 ----a-w C:\WINDOWS\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2007-11-07 14:23:07 1,224,704 ----a-w C:\WINDOWS\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2007-11-08 22:03:58 1,232,896 ----a-w C:\WINDOWS\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2007-11-08 22:04:18 61,440 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_1669b663\CustomMarshalers.dll
+ 2007-11-08 22:06:57 3,391,488 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_32082f61\mscorlib.dll
+ 2007-11-08 22:06:27 1,470,464 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_cdbf5e69\System.Design.dll
+ 2007-11-08 22:04:21 90,112 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_49a10cad\System.Drawing.Design.dll
+ 2007-11-08 22:06:49 835,584 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_98b99f43\System.Drawing.dll
+ 2007-11-08 22:04:33 3,018,752 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_59c7c667\System.Windows.Forms.dll
+ 2007-11-08 22:04:47 2,088,960 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_bf67e60b\System.Xml.dll
+ 2007-11-08 22:04:13 1,966,080 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_0c8443a8\System.dll
- 2004-07-15 06:49:16 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2007-04-14 02:30:52 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2004-07-15 06:49:22 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2007-04-14 02:30:52 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2004-07-15 05:32:22 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2007-04-14 01:57:52 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2003-02-21 02:09:14 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2007-04-14 01:57:58 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2004-07-15 05:25:06 315,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2007-04-14 01:56:30 315,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2004-07-15 05:33:04 102,400 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2007-04-14 01:58:00 102,400 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2004-07-15 19:29:02 2,138,112 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2007-04-14 01:50:46 2,142,208 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
- 2003-02-21 02:09:18 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2007-04-14 01:58:02 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2004-07-15 05:26:52 2,510,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2007-04-14 01:57:00 2,523,136 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2004-07-15 05:28:34 2,502,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2007-04-14 01:57:28 2,514,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- 2004-08-10 21:20:00 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2007-01-15 21:11:26 73,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2004-07-15 06:49:16 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3096\_aspnet_isapi.dll
+ 2004-07-15 05:32:22 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3096\_CORPerfMonExt.dll
+ 2004-07-15 05:24:30 282,624 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3096\_fusion.dll
+ 2004-07-15 05:25:06 315,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3096\_mscorjit.dll
+ 2004-07-15 19:29:02 2,138,112 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3096\_mscorlib.dll
+ 2003-02-21 02:09:18 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3096\_mscorsn.dll
+ 2004-07-15 05:26:52 2,510,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3096\_mscorsvr.dll
+ 2004-07-15 05:28:34 2,502,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3096\_mscorwks.dll
+ 2003-02-21 11:42:22 348,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3096\_msvcr71.dll
+ 2004-07-15 05:34:50 94,208 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3096\_PerfCounter.dll
- 2004-07-15 19:31:16 1,224,704 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2007-04-14 02:35:38 1,232,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2004-07-15 19:29:00 1,257,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2007-04-14 02:35:46 1,265,664 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2004-07-15 05:24:50 155,648 ----a-w C:\WINDOWS\system32\mscoree.dll
+ 2006-12-22 17:28:14 271,360 ----a-w C:\WINDOWS\system32\mscoree.dll
+ 2006-12-22 18:02:36 6,144 ----a-w C:\WINDOWS\system32\mui\
0409\mscorees.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{134E2CE7-A68C-4637-897F-CF4205412A41}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2a4a3077-bbe4-4fbf-9c98-1a9d89e89e6f}]
2007-11-07 01:36 79936 --a------ C:\WINDOWS\system32\sidrynms.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3B0F84BD-A9AD-4A39-882D-6DEB07C201A4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{48B2A1DE-6706-47D2-9F2F-E661058355EC}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4F529B6C-0DA9-454F-BD05-048D8CFBA341}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{634BBAB7-3F60-4426-944F-A62B9007F67F}]
2007-11-05 01:35 36352 --a------ C:\WINDOWS\system32\byxvvts.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B8FD002F-CF51-4009-8A21-A015CA9128F5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C0D603AB-4EBC-4631-A9F3-E79DEC645981}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C595F5B6-9801-4165-BA1E-43FD68E8AC89}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXBTCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll" [2004-03-17 11:30]
"5417482f"="C:\WINDOWS\system32\qjrdrgyk.dll" []
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 12:51]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{634BBAB7-3F60-4426-944F-A62B9007F67F}"= C:\WINDOWS\system32\byxvvts.dll [2007-11-05 01:35 36352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxvvts]
byxvvts.dll 2007-11-05 01:35 36352 C:\WINDOWS\system32\byxvvts.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\llxskwna]
llxskwna.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ssqro.dll
R0 IFP700;iRiver Internet Audio Player IFP-700;C:\WINDOWS\system32\drivers\ifp700.sys
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb6fa1df-7785-11dc-807e-0011115ccae9}]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2007-11-08 22:39:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-12 17:39:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-12 13:25:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-12 13:28:16 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-07 18:36
C:\ComboFix3.txt ... 2007-11-07 01:45
.
--- E O F ---