ComboFix 08-04-03.2 - micky 2008-04-03 19:47:17.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.679 [GMT 1:00]
Running from: C:\Documents and Settings\micky\Local Settings\Temporary Internet Files\Content.IE5\43YWU2YE\ComboFix[1].exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\lehglter.ini
C:\WINDOWS\system32\OYceOqss.ini
C:\WINDOWS\system32\OYceOqss.ini2
C:\WINDOWS\system32\retlghel.dll
C:\WINDOWS\system32\ssqOecYO.dll
C:\WINDOWS\system32\yjfymicq.dll
C:\WINDOWS\system32\yteaqkqe.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-03 to 2008-04-03 )))))))))))))))))))))))))))))))
.
2008-04-03 19:01 . 2008-04-03 19:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-03 18:50 . 2008-04-03 18:50 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-03 18:27 . 2008-04-03 18:42 <DIR> d-------- C:\Program Files\RogueRemover FREE
2008-04-03 18:20 . 2008-04-03 18:20 <DIR> d-------- C:\Program Files\Yahoo!
2008-04-03 14:39 . 2008-04-03 16:11 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-04-03 14:36 . 2008-04-03 16:12 <DIR> d-------- C:\Documents and Settings\micky\.housecall6.6
2008-04-03 12:30 . 2008-04-03 12:31 132,785,556 --a------ C:\SYM_REGISTRY_BACKUP.reg
2008-04-03 00:34 . 2008-04-03 00:34 <DIR> d-------- C:\Program Files\ffdshow
2008-04-03 00:33 . 2008-04-03 00:33 <DIR> d-------- C:\Program Files\x264
2008-04-03 00:33 . 2008-04-03 00:33 580,114 --a------ C:\WINDOWS\system32\x264vfw.dll
2008-04-02 22:50 . 2008-04-02 22:50 <DIR> d-------- C:\ie-spyad_zo
2008-04-01 13:44 . 2008-04-02 13:45 1,581,392 --ahs---- C:\WINDOWS\system32\rhuvgpxn.ini
2008-03-31 13:47 . 2008-04-01 10:31 1,597,323 --ahs---- C:\WINDOWS\system32\ykspkmfn.ini
2008-03-31 02:06 . 2008-04-03 00:32 <DIR> d-------- C:\Program Files\Winamp
2008-03-31 01:35 . 2008-03-31 01:35 36,352 --a------ C:\WINDOWS\system32\hgGxXqRi.dll
2008-03-30 18:52 . 2008-03-30 18:59 <DIR> d-------- C:\Program Files\AMD
2008-03-30 18:41 . 2008-03-30 18:41 <DIR> d-------- C:\Program Files\NVIDIA nTune Performance Application
2008-03-24 01:23 . 2008-03-24 01:23 284 --a------ C:\Documents and Settings\micky\Application Data\ViewerApp.dat
2008-03-24 00:24 . 2003-12-03 18:44 13,566 --a------ C:\WINDOWS\system32\drivers\cdrbsvsd.sys
2008-03-24 00:05 . 2004-08-04 00:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-03-24 00:05 . 2004-08-04 00:10 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys
2008-03-24 00:05 . 2004-08-03 23:58 5,376 --a------ C:\WINDOWS\system32\MSPCLOCK.sys
2008-03-23 23:53 . 2001-11-05 10:23 299,923 --a------ C:\WINDOWS\system32\drivers\sonyhcs.sys
2008-03-23 23:53 . 2002-10-15 23:41 102,220 --a------ C:\WINDOWS\system32\drivers\sonypvs1.sys
2008-03-23 23:53 . 2001-07-03 21:33 53,248 --a------ C:\WINDOWS\system32\SONYHCY.DLL
2008-03-23 23:53 . 2001-11-05 10:23 38,739 --a------ C:\WINDOWS\system32\drivers\sonyhcc.sys
2008-03-23 23:53 . 2001-11-05 10:23 6,097 --a------ C:\WINDOWS\system32\drivers\sonyhcb.sys
2008-03-23 23:53 . 2001-07-03 21:39 3,654 --a------ C:\WINDOWS\system32\drivers\Sonyhcp.dll
2008-03-12 02:11 . 2008-03-12 02:18 <DIR> d-------- C:\Program Files\Absolute MP3 Splitter
2008-03-05 01:57 . 2008-03-05 01:57 <DIR> d-------- C:\Documents and Settings\micky\dwhelper
2008-03-04 20:45 . 2008-03-04 20:45 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-03-04 20:44 . 2008-03-04 20:45 <DIR> d-------- C:\Documents and Settings\micky\Application Data\SystemRequirementsLab
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-03 18:41 --------- d-----w C:\Documents and Settings\micky\Application Data\Azureus
2008-04-03 13:21 --------- d-----w C:\Documents and Settings\micky\Application Data\NewsBin
2008-04-02 13:25 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-01 14:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-03-26 20:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-25 21:38 --------- d-----w C:\Documents and Settings\micky\Application Data\LimeWire
2008-03-24 14:28 --------- d-----w C:\Program Files\WinAVIVideoConverter
2008-03-24 14:28 --------- d-----w C:\Program Files\WinAVI Video Converter
2008-03-24 10:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-03-20 09:22 --------- d-----w C:\Program Files\NetProject
2008-03-12 07:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-11 22:04 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-03-08 21:26 --------- d-----w C:\Program Files\TVUPlayer
2008-03-08 10:38 --------- d-----w C:\Program Files\Soulseek-Test
2008-03-08 00:55 --------- d-----w C:\Program Files\Azureus
2008-03-03 08:20 --------- d-----w C:\Program Files\SWAT 4
2008-02-26 20:42 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-26 20:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-02-26 20:36 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-02-26 13:03 --------- d-----w C:\Program Files\iTunes
2008-02-26 13:03 --------- d-----w C:\Program Files\iPod
2008-02-26 13:01 --------- d-----w C:\Program Files\QuickTime
2008-02-22 16:33 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-22 16:33 --------- d-----w C:\Program Files\AntiSpyKit 5.3
2008-02-22 09:43 --------- d-----w C:\Program Files\Sotfone
2008-02-07 21:57 --------- d-----w C:\Program Files\ESET
.
((((((((((((((((((((((((((((( snapshot@2008-04-03_11.39.37.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-09-03 08:14:10 578,848 ----a-w C:\WINDOWS\Downloaded Program Files\tgctlsr.dll
- 2000-08-31 07:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-20 19:02:28 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
- 2000-08-31 07:00:00 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2005-10-20 19:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2000-08-31 07:00:00 73,728 ----a-w C:\WINDOWS\fdsv.exe
+ 2000-08-31 07:00:00 80,412 ----a-w C:\WINDOWS\grep.exe
+ 2000-08-31 07:00:00 98,816 ----a-w C:\WINDOWS\sed.exe
+ 2000-08-31 07:00:00 161,792 ----a-w C:\WINDOWS\swreg.exe
+ 2000-08-31 07:00:00 136,704 ----a-w C:\WINDOWS\swsc.exe
+ 2000-08-31 07:00:00 212,480 ----a-w C:\WINDOWS\swxcacls.exe
+ 2008-04-03 19:04:40 40,960 ----a-w C:\WINDOWS\TEMP\rtdrvmon.exe
+ 2000-08-31 07:00:00 49,152 ----a-w C:\WINDOWS\VFind.exe
+ 2000-08-31 07:00:00 68,096 ----a-w C:\WINDOWS\zip.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C4F31A60-D2C7-4B22-ACE9-AE33C94D7316}]
2008-03-31 01:35 36352 --a------ C:\WINDOWS\system32\hgGxXqRi.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 14:39 1289000]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2006-09-14 18:54 53248 C:\WINDOWS\system32\VTTimer.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 20:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-08-27 17:18 949376]
"lxbkbmgr.exe"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2007-04-26 13:02 74672]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"AODAssist.exe"="C:\Program Files\AMD\AMD OverDrive\AODAssist.exe" [2007-10-23 17:50 42496]
"RaidTool"="C:\Program Files\VIA\RAID\raid_tool.exe" [2004-10-11 15:54 589824]
"lxbymon.exe"="C:\Program Files\Lexmark P910 Series\lxbymon.exe" [ ]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2007-04-26 13:02 74672]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"EzPrint"="C:\Program Files\Lexmark P910 Series\ezprint.exe" [ ]
"C-Media Mixer"="Mixer.exe" [2002-10-15 18:00 1818624 C:\WINDOWS\mixer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 20:00 15360]
"Power2GoExpress"="C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" [2004-11-06 09:38 1359967]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{C4F31A60-D2C7-4B22-ACE9-AE33C94D7316}"= C:\WINDOWS\system32\hgGxXqRi.dll [2008-03-31 01:35 36352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hgGxXqRi]
hgGxXqRi.dll 2008-03-31 01:35 36352 C:\WINDOWS\system32\hgGxXqRi.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\Msmsgs.exe" /background
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
"Google Update"="C:\Documents and Settings\micky\Local Settings\Application Data\Google\Update\1.1.17.0\GoogleUpdate.exe" /lang en
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCEyeLic"=C:\Program Files\PCEye2000\pceye2000.exe
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
"TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
"LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE
"SoftickPPP"="C:\Program Files\Softick\PPP\Bin\PPPGate.exe"
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"AudioDeck"=C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
"Recguard"=C:\WINDOWS\SMINST\RECGUARD.EXE
"VTTrayp"=VTtrayp.exe
"RaidTool"=C:\Program Files\VIA\RAID\raid_tool.exe
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\WINDOWS\\system32\\lxbkcoms.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12513:TCP"= 12513:TCP:BitComet 12513 TCP
"12513:UDP"= 12513:UDP:BitComet 12513 UDP
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 viaide1;viaide1;C:\WINDOWS\system32\DRIVERS\VIAIDEXP.SYS [2001-10-18 12:00]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2007-09-21 18:49]
R2 lxbk_device;lxbk_device;C:\WINDOWS\system32\lxbkcoms.exe [2007-04-26 13:01]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 20:00]
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys [2002-10-15 23:41]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2007-12-22 02:09]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a187a587-efa4-11dc-a1bd-0013d3ab235b}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-03-28 17:19:59 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
"2008-04-01 08:01:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-03 20:05:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\hgGxXqRi.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-04-03 20:13:03 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-03 19:12:42
ComboFix2.txt 2008-04-03 10:43:14
Pre-Run: 19,760,779,264 bytes free
Post-Run: 19,804,028,928 bytes free
.
2008-03-12 07:46:33 --- E O F ---