ComboFix 08-06-20.4 - Karah 2008-06-27 3:21:49.9 - NTFSx86
Running from: C:\Documents and Settings\All Users\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Program Files\Antivirus 2008 PRO
C:\Program Files\Antivirus 2008 PRO\antivirus-2008pro.exe
C:\Program Files\Antivirus 2008 PRO\vscan.tsi
C:\Program Files\Antivirus 2008 PRO\zlib.dll
C:\WINDOWS\cookies.ini
C:\WINDOWS\enlx.exe
C:\WINDOWS\system32\awtuuvWm.dll
C:\WINDOWS\system32\baHklUvw.ini
C:\WINDOWS\system32\baHklUvw.ini2
C:\WINDOWS\system32\CIPWFfii.ini
C:\WINDOWS\system32\CIPWFfii.ini2
C:\WINDOWS\system32\iapmehrp.ini
C:\WINDOWS\system32\iifFWPIC.dll
C:\WINDOWS\system32\jisagvsw.ini
C:\WINDOWS\system32\kjjklnmp.ini
C:\WINDOWS\system32\kjjklnmp.ini2
C:\WINDOWS\system32\mWvuutwa.ini
C:\WINDOWS\system32\mWvuutwa.ini2
C:\WINDOWS\system32\ooxpdkrv.ini
C:\WINDOWS\system32\pmnlkjjk.dll
C:\WINDOWS\system32\vpjactsw.ini
C:\WINDOWS\system32\wvUlkHab.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-27 to 2008-06-27 )))))))))))))))))))))))))))))))
.
2008-06-27 02:52 . 2008-06-27 02:52 294 ---hs---- C:\WINDOWS\system32\ooxpdkrv.ini
2008-06-27 02:01 . 2008-06-27 02:01 92,032 --a------ C:\WINDOWS\system32\vrkdpxoo.dll
2008-06-26 01:41 . 2008-06-26 01:41 92,544 --a------ C:\WINDOWS\system32\lxmyjpdt.dll
2008-06-26 01:41 . 2008-06-26 01:40 354 --ahs---- C:\WINDOWS\system32\tdpjymxl.ini
2008-06-26 01:30 . 2008-06-26 01:40 354 --ahs---- C:\WINDOWS\system32\vpjactsw.ini
2008-06-25 23:01 . 2008-06-25 23:01 28,800 --a------ C:\WINDOWS\system32\cbXrOGAS.dll
2008-06-25 22:57 . 2008-06-25 18:00 245,760 --a------ C:\WINDOWS\gfetqaxsqsb.dll
2008-06-25 22:57 . 2008-06-25 18:00 229,376 --a------ C:\WINDOWS\pntqkflv.dll
2008-06-25 22:57 . 2008-06-25 18:00 180,224 --a------ C:\WINDOWS\qegbdmwf.dll
2008-06-25 22:57 . 2008-06-25 18:00 151,552 --a------ C:\WINDOWS\gxvpsafm.dll
2008-06-25 22:57 . 2008-06-25 18:00 81,920 --a------ C:\WINDOWS\tovafrnm.exe
2008-06-23 22:06 . 2008-06-27 01:04 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-06-23 20:05 . 2008-06-23 20:05 <DIR> d-------- C:\Deckard
2008-06-23 11:42 . 2008-06-23 11:42 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-23 10:44 . 2008-06-25 10:48 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-06-23 10:44 . 2008-06-23 10:44 <DIR> d-------- C:\Documents and Settings\blah\Application Data\PC Tools
2008-06-23 10:44 . 2008-06-10 21:22 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-06-23 10:44 . 2008-06-02 15:19 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-06-23 10:44 . 2008-06-02 15:19 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-06-23 10:44 . 2008-06-02 15:19 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-06-23 10:42 . 2008-06-23 11:34 <DIR> d-------- C:\Documents and Settings\blah\Application Data\U3
2008-06-23 10:24 . 2003-11-12 20:03 <DIR> d-------- C:\Documents and Settings\blah\Application Data\Symantec
2008-06-23 10:24 . 2008-06-23 10:24 <DIR> d-------- C:\Documents and Settings\blah
2008-06-22 21:24 . 2008-06-22 21:24 86 --a------ C:\WINDOWS\wininit.ini
2008-06-22 19:08 . 2008-06-22 19:07 691,545 --a------ C:\WINDOWS\unins002.exe
2008-06-22 19:08 . 2008-06-22 19:08 2,541 --a------ C:\WINDOWS\unins002.dat
2008-06-22 03:07 . 2008-06-22 03:07 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-06-21 21:56 . 2008-06-21 21:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd
2008-06-21 00:47 . 2008-06-21 00:47 <DIR> d-------- C:\bios
2008-06-20 22:24 . 2008-06-20 22:24 94,208 --a------ C:\WINDOWS\DIIUnin.exe
2008-06-20 22:24 . 2008-06-20 22:33 18,340 --a------ C:\WINDOWS\DIIUnin.dat
2008-06-20 22:24 . 2008-06-20 22:24 2,829 --a------ C:\WINDOWS\DIIUnin.pif
2008-06-20 19:08 . 2008-06-20 22:26 21,840 --a----t- C:\WINDOWS\system32\SIntfNT.dll
2008-06-20 19:08 . 2008-06-20 22:26 17,212 --a----t- C:\WINDOWS\system32\SIntf32.dll
2008-06-20 19:08 . 2008-06-20 22:26 12,067 --a----t- C:\WINDOWS\system32\SIntf16.dll
2008-06-20 18:47 . 2008-06-26 19:39 <DIR> d-------- C:\Program Files\Diablo II
2008-06-11 18:55 . 2008-06-11 18:55 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-26 06:40 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-26 06:13 --------- d-----w C:\Program Files\CallWave
2008-06-24 05:58 --------- d-sh--w C:\Program Files\WGV
2008-06-23 00:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-23 00:17 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-21 05:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-13 09:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-21 07:04 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-21 07:04 659,456 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2008-04-21 07:04 615,936 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2008-04-21 07:04 474,112 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
2008-04-21 07:04 1,494,528 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
2008-04-17 10:52 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
2005-01-21 16:45 56 -csh--r C:\WINDOWS\system32\E7D092101B.sys
2005-01-21 16:45 1,682 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-23_11.27.21.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-23 16:17:30 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-27 08:17:08 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-29 13:49:06 456,768 ----a-w C:\WINDOWS\Downloaded Program Files\wlscBase.dll
+ 2005-10-21 01:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2008-06-21 04:42:34 63,386 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-06-24 02:59:09 63,386 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-06-21 04:42:34 404,206 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-06-24 02:59:09 404,206 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39D67F39-6F48-438A-80A2-F86FE363C215}]
2008-06-25 23:01 28800 --a------ C:\WINDOWS\system32\cbXrOGAS.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{63EE8DD1-D0EB-4A34-B133-E38B41307B27}]
2008-06-25 18:00 245760 --a------ C:\WINDOWS\gfetqaxsqsb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
2008-06-12 18:29 237056 --a------ c:\program files\peoplepc\toolbar\ppctoolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A8FB8EB3-183B-4598-924D-86F0E5E37085}"= "c:\program files\peoplepc\toolbar\ppctoolbar.dll" [2008-06-12 18:29 237056]
[HKEY_CLASSES_ROOT\clsid\{a8fb8eb3-183b-4598-924d-86f0e5e37085}]
[HKEY_CLASSES_ROOT\PeoplePC.Toolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{994D628D-4D22-4DB9-B6DB-F7D9F1635817}]
[HKEY_CLASSES_ROOT\PeoplePC.Toolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A8FB8EB3-183B-4598-924D-86F0E5E37085}"= c:\program files\peoplepc\toolbar\ppctoolbar.dll [2008-06-12 18:29 237056]
[HKEY_CLASSES_ROOT\clsid\{a8fb8eb3-183b-4598-924d-86f0e5e37085}]
[HKEY_CLASSES_ROOT\PeoplePC.Toolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{994D628D-4D22-4DB9-B6DB-F7D9F1635817}]
[HKEY_CLASSES_ROOT\PeoplePC.Toolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"NCLaunch"="C:\WINDOWS\NCLAUNCH.EXe" [2007-03-17 14:25 40960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-02-07 01:24 100056]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-04 02:56 158208]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-06-01 11:58:00 113664]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{39D67F39-6F48-438A-80A2-F86FE363C215}"= C:\WINDOWS\system32\cbXrOGAS.dll [2008-06-25 23:01 28800]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXrOGAS]
cbXrOGAS.dll 2008-06-25 23:01 28800 C:\WINDOWS\system32\cbXrOGAS.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CallWave.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CallWave.lnk
backup=C:\WINDOWS\pss\CallWave.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SBC Self Support Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SBC Self Support Tool.lnk
backup=C:\WINDOWS\pss\SBC Self Support Tool.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Karah^Start Menu^Programs^Startup^Microsoft Office Groove.lnk]
path=C:\Documents and Settings\Karah\Start Menu\Programs\Startup\Microsoft Office Groove.lnk
backup=C:\WINDOWS\pss\Microsoft Office Groove.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4a8733d9]
--a------ 2008-06-27 02:01 92032 C:\WINDOWS\system32\vrkdpxoo.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
--a------ 2008-06-10 21:22 1163656 C:\Program Files\Spyware Doctor\pctsTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
"sdCoreService"=2 (0x2)
"sdAuxService"=2 (0x2)
"Microsoft Office Groove Audit Service"=3 (0x3)
"SBService"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"= C:\\Program Files\\Yahoo!\\Messenger\\YPAGER.EXE
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= C:\\Program Files\\Yahoo!\\Messenger\\yserver.exe
"C:\\WINDOWS\\system32\\mshta.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\WINDOWS\\system32\\lxdccoms.exe"=
"C:\\Program Files\\Lexmark 1300 Series\\lxdcamon.exe"=
"C:\\Program Files\\Lexmark 1300 Series\\App4R.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdcpswx.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdcjswx.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdctime.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdcwbgw.exe"=
"C:\\Program Files\\CallWave\\IAM.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
"1863:TCP"= 1863:TCP:MSN Messenger
"6891:TCP"= 6891:TCP:Open Port 1
"6892:TCP"= 6892:TCP:Open Port 2
"6893:TCP"= 6893:TCP:Open Port 3
"6894:TCP"= 6894:TCP:Open Port 4
"6895:TCP"= 6895:TCP:Open Port 5
R2 lxdc_device;lxdc_device;C:\WINDOWS\system32\lxdccoms.exe [2007-04-30 15:03]
R2 lxdcCATSCustConnectService;lxdcCATSCustConnectService;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdcserv.exe [2007-04-30 15:04]
S3 naecd;naecd;C:\DOCUME~1\Karah\LOCALS~1\Temp\naecd.sys []
S3 PhDebug32;PhDebug32;c:\bios\hr60\debug32.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a841e248-9851-11dc-aed3-c724e8a54708}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-02-05 19:32:18 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-27 05:09:46 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-27 03:32:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
C:\WINDOWS\explorer.exe [132] 0x82DE8020
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
-> C:\WINDOWS\system32\cbXrOGAS.dll
.
Completion time: 2008-06-27 4:02:53
ComboFix-quarantined-files.txt 2008-06-27 09:02:35
ComboFix2.txt 2008-06-23 17:37:22
ComboFix3.txt 2008-06-23 16:28:19
Pre-Run: 14,287,036,416 bytes free
Post-Run: 14,270,816,256 bytes free
243 --- E O F --- 2008-06-22 08:07:48