Part 4
Here is the Combofix log -->
ComboFix 07-12-02.6 - Cathy 2007-12-06 19:09:26.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.165 [GMT -5:00]
Running from: C:\Documents and Settings\Cathy\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Cathy\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\Documents and Settings\Cathy\Start Menu\Programs\Startup\TA_Start.lnk
C:\WINDOWS\df87173.exe
C:\WINDOWS\hg173.exe
C:\WINDOWS\io43mvuiw4kj.exe
C:\WINDOWS\system32\cbxvttq.dll
C:\WINDOWS\system32\gsmfcpft.ini
C:\WINDOWS\system32\gwcbgibh.ini
C:\WINDOWS\system32\jkkljhh.dll
C:\WINDOWS\system32\kjdsrngq.exe
C:\WINDOWS\system32\mkjocfdi.ini
C:\WINDOWS\system32\popoq.bak1
C:\WINDOWS\system32\popoq.bak2
C:\WINDOWS\system32\popoq.ini2
C:\WINDOWS\system32\psdmgfbr.dll
C:\WINDOWS\system32\wccjpacx.dll
C:\WINDOWS\system32\weicqvrp.ini
C:\WINDOWS\system32\xjconveq.dll
C:\WINDOWS\system32\yiarkiig.ini
C:\WINDOWS\system32\zxcrmbrd.dll
C:\WINDOWS\system32\zxcrmbrd.dllbox
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Cathy\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Cathy\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Cathy\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Cathy\Start Menu\Programs\Startup\TA_Start.lnk
C:\Program Files\Caioygmb
C:\Program Files\Caioygmb\zhwznfaa.dll
C:\Program Files\Cfddenxf
C:\Program Files\Cfddenxf\vqgtchvw.dll
C:\Program Files\Cool
C:\Program Files\Cool\un_CoolSetup_15849.txt
C:\Program Files\Evkbivxi
C:\Program Files\Evkbivxi\fvmezoip.dll
C:\Program Files\folder.js\
C:\Program Files\Fstmvibi
C:\Program Files\Fstmvibi\txncgbji.dll
C:\Program Files\Lytzhgpl
C:\Program Files\Lytzhgpl\mxithnbm.dll
C:\Program Files\Qfsjjupr
C:\Program Files\Qfsjjupr\mziqpmlb.dll
C:\Temp
C:\WINDOWS\df87173.exe
C:\WINDOWS\hg173.exe
C:\WINDOWS\io43mvuiw4kj.exe
C:\WINDOWS\system32\cbxvttq.dll
C:\WINDOWS\system32\cc1
C:\WINDOWS\system32\gsmfcpft.ini
C:\WINDOWS\system32\gwcbgibh.ini
C:\WINDOWS\system32\jkkljhh.dll
C:\WINDOWS\system32\kjdsrngq.exe
C:\WINDOWS\system32\mkjocfdi.ini
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\popoq.bak1
C:\WINDOWS\system32\popoq.bak2
C:\WINDOWS\system32\popoq.ini2
C:\WINDOWS\system32\psdmgfbr.dll
C:\WINDOWS\system32\tnrtmwuk
C:\WINDOWS\system32\tnrtmwuk\bg1.gif
C:\WINDOWS\system32\tnrtmwuk\bgtop.gif
C:\WINDOWS\system32\tnrtmwuk\bottom1.gif
C:\WINDOWS\system32\tnrtmwuk\essentials.gif
C:\WINDOWS\system32\tnrtmwuk\icon1.ico
C:\WINDOWS\system32\tnrtmwuk\install1.gif
C:\WINDOWS\system32\tnrtmwuk\left1.gif
C:\WINDOWS\system32\tnrtmwuk\li.gif
C:\WINDOWS\system32\tnrtmwuk\logo.gif
C:\WINDOWS\system32\tnrtmwuk\main.htm
C:\WINDOWS\system32\tnrtmwuk\mainframe.htm
C:\WINDOWS\system32\tnrtmwuk\reinstall1.gif
C:\WINDOWS\system32\tnrtmwuk\right1.gif
C:\WINDOWS\system32\tnrtmwuk\s1.htm
C:\WINDOWS\system32\tnrtmwuk\s2.htm
C:\WINDOWS\system32\tnrtmwuk\s3.htm
C:\WINDOWS\system32\tnrtmwuk\SMTop1.gif
C:\WINDOWS\system32\tnrtmwuk\SMTop2.gif
C:\WINDOWS\system32\tnrtmwuk\SMTop3.gif
C:\WINDOWS\system32\tnrtmwuk\SMTop4.gif
C:\WINDOWS\system32\tnrtmwuk\soft1_off.gif
C:\WINDOWS\system32\tnrtmwuk\soft1_off_ext.gif
C:\WINDOWS\system32\tnrtmwuk\soft1_on.gif
C:\WINDOWS\system32\tnrtmwuk\soft1_on_ext.gif
C:\WINDOWS\system32\tnrtmwuk\soft2_off.gif
C:\WINDOWS\system32\tnrtmwuk\soft2_off_ext.gif
C:\WINDOWS\system32\tnrtmwuk\soft2_on.gif
C:\WINDOWS\system32\tnrtmwuk\soft2_on_ext.gif
C:\WINDOWS\system32\tnrtmwuk\soft3_off.gif
C:\WINDOWS\system32\tnrtmwuk\soft3_off_ext.gif
C:\WINDOWS\system32\tnrtmwuk\soft3_on.gif
C:\WINDOWS\system32\tnrtmwuk\soft3_on_ext.gif
C:\WINDOWS\system32\tnrtmwuk\softbottom_off.gif
C:\WINDOWS\system32\tnrtmwuk\softbottom_on.gif
C:\WINDOWS\system32\tnrtmwuk\softleft_off.gif
C:\WINDOWS\system32\tnrtmwuk\softleft_on.gif
C:\WINDOWS\system32\tnrtmwuk\top1.gif
C:\WINDOWS\system32\tnrtmwuk\top2.gif
C:\WINDOWS\system32\tnrtmwuk\turnoff1.gif
C:\WINDOWS\system32\tnrtmwuk\turnon1.gif
C:\WINDOWS\system32\wccjpacx.dll
C:\WINDOWS\system32\weicqvrp.ini
C:\WINDOWS\system32\xjconveq.dll
C:\WINDOWS\system32\yiarkiig.ini
C:\WINDOWS\system32\zxcrmbrd.dll
C:\WINDOWS\system32\zxcrmbrd.dllbox
.
((((((((((((((((((((((((( Files Created from 2007-11-07 to 2007-12-07 )))))))))))))))))))))))))))))))
.
2007-12-01 00:56 . 2007-12-01 00:56 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2007-12-01 00:42 . 2007-12-01 00:42 0 --a------ C:\WINDOWS\nsreg.dat
2007-11-29 16:22 . 2007-12-01 02:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2007-11-28 21:16 . 2007-08-20 05:04 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-11-28 21:16 . 2007-08-20 05:04 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-11-28 21:16 . 2007-08-17 05:20 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-11-28 21:15 . 2007-08-20 05:04 6,058,496 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-11-28 21:15 . 2007-04-17 04:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-11-28 21:15 . 2007-03-08 00:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-11-28 21:15 . 2007-08-20 05:04 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-11-28 21:15 . 2007-08-20 05:04 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-11-28 21:15 . 2007-08-20 05:04 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-11-21 09:49 . 2007-12-01 00:43 1,148,902 --a------ C:\Install
2007-11-21 09:48 . 2007-11-21 09:48 <DIR> d-------- C:\Program Files\furibuni
2007-11-14 21:03 . 2007-11-14 21:03 1,985 --a------ C:\WINDOWS\system32\MRT.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-06 06:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-01 09:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-01 06:10 --------- d-----w C:\Program Files\Common Files\Motive
2007-12-01 05:11 --------- d-----w C:\Program Files\Verizon
2007-12-01 05:05 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-01 04:58 --------- d-----w C:\Documents and Settings\Cathy\Application Data\Verizon
2007-12-01 04:23 --------- d-----w C:\Program Files\LimeWire
2007-12-01 04:07 --------- d-----w C:\Program Files\AIM
2007-12-01 04:06 --------- d-----w C:\Documents and Settings\Cathy\Application Data\Aim
2007-12-01 04:05 --------- d-----w C:\Program Files\AIM+
2007-11-24 02:15 --------- d-----w C:\Program Files\lx_cats
2007-06-14 09:22 2,231 ----a-w C:\Program Files\folder.js
2007-04-28 19:52 439,296 ----a-w C:\Documents and Settings\Cathy\GoToAssist_phone__317_en.exe
.
((((((((((((((((((((((((((((( snapshot@2007-12-06_ 6.57.34.92 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-06 11:14:54 53,166 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-12-06 11:59:36 53,166 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-12-06 11:14:54 380,918 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-12-06 11:59:37 380,918 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 19:05]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-06-25 14:30]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-07-17 12:50]
"TV Now"="C:\Program Files\HPQ\Notebook Utilities\TvNow.exe" [2003-01-30 09:34]
"Display Settings"="C:\Program Files\HPQ\Notebook Utilities\hptasks.exe" [2002-08-15 05:26]
"QT4HPOT"="C:\Program Files\HPQ\One-Touch\OneTouch.EXE" [2003-10-03 14:07]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2003-03-26 10:15]
"lxcymon.exe"="C:\Program Files\Lexmark 3400 Series\lxcymon.exe" [2006-03-06 12:48]
"EzPrint"="C:\Program Files\Lexmark 3400 Series\ezprint.exe" [2006-02-07 00:10]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2006-02-02 03:11]
"LXCYCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [2006-02-24 06:54]
"VerizonServicepoint.exe"="C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe [2002-09-16 14:42:06]
KODAK Software Updater.lnk - C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe [2002-03-13 07:08:34]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CARPService"=carpserv.exe
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
"Symantec NetDriver Monitor"=C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
R3 CALIAUD;Conexant AMC 3D Environmental Audio;C:\WINDOWS\system32\drivers\caliaud.sys
R3 CALIHALA;CALIHALA;C:\WINDOWS\system32\drivers\calihal.sys
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.SYS
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;C:\WINDOWS\system32\DRIVERS\DP83815.SYS
R3 lxcy_device;lxcy_device;C:\WINDOWS\system32\lxcycoms.exe -service
S3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys
S3 hamachi_oem;PlayLinc Adapter;C:\WINDOWS\system32\DRIVERS\gan_adapter.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a67329e0-5a18-11db-bf31-00038a000015}]
\Shell\AutoRun\command - F:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-01 01:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Theresa.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
"2007-12-06 22:32:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-06 19:18:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????4?9?1?7??????? ?deB???????????????B? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-06 19:20:09 - machine was rebooted
C:\ComboFix2.txt ... 2007-12-06 07:00
.
--- E O F ---
thanks again