Combofix log:
ComboFix 08-04-08.4 - LuBo 2008-04-09 6:41:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1251.1.1033.18.576 [GMT -4:00]
Running from: C:\Documents and Settings\LuBo\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
TimedOut: progfile.dat
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMeb47631c.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\cdhfciuh.dll
C:\WINDOWS\system32\iSsYaccf.ini
C:\WINDOWS\system32\iSsYaccf.ini2
C:\WINDOWS\system32\QAbHRqru.ini2
C:\WINDOWS\system32\QBJTtBeg.ini2
C:\WINDOWS\system32\QYyxaGgh.ini2
C:\WINDOWS\system32\Sttsvyxx.ini2
C:\WINDOWS\system32\vtUmkhET.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-09 to 2008-04-09 )))))))))))))))))))))))))))))))
.
2008-04-08 22:00 . 2008-04-08 22:00 127 --a------ C:\WINDOWS\system32\MRT.INI
2008-04-08 14:15 . 2008-04-08 14:15 83,520 --a------ C:\WINDOWS\system32\dymfbbbe.dll.vir
2008-04-08 14:15 . 2008-04-08 14:15 294 ---hs---- C:\WINDOWS\system32\ebbbfmyd.ini
2008-04-08 14:09 . 2008-04-08 14:09 3,648 --a------ C:\WINDOWS\system32\ikyosqoc.dll
2008-04-08 13:56 . 2008-04-08 13:56 267,776 --a------ C:\WINDOWS\system32\cbXOHXPJ.dll.vir
2008-04-08 13:53 . 2008-04-08 13:55 <DIR> d-------- C:\Program Files\Trojan Remover
2008-04-08 13:53 . 2008-04-08 13:53 <DIR> d-------- C:\Documents and Settings\LuBo\Application Data\Simply Super Software
2008-04-08 13:53 . 2008-04-08 13:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-04-08 13:53 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-04-08 13:53 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-04-08 13:53 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-04-08 13:53 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-04-08 13:53 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-04-08 13:45 . 2008-04-08 13:45 3,648 --a------ C:\WINDOWS\system32\qxjkynny.dll
2008-04-08 06:37 . 2008-04-08 06:37 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-07 23:09 . 2008-04-08 13:24 <DIR> d-------- C:\VundoFix Backups
2008-04-07 14:10 . 2008-04-07 21:16 <DIR> d-------- C:\Program Files\LimeWire
2008-04-07 14:00 . 2008-04-07 14:00 36,352 --a------ C:\WINDOWS\system32\awtrogde.dll.ren
2008-04-06 11:07 . 2008-04-06 11:07 <DIR> d-------- C:\Program Files\MP3 Remix
2008-03-30 12:55 . 2008-03-30 19:30 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-30 01:13 . 2008-04-06 10:37 <DIR> d-------- C:\Program Files\SwiftKit
2008-03-30 01:13 . 2008-03-30 19:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SwiftKit
2008-03-27 13:25 . 2008-03-27 13:25 <DIR> d-------- C:\Documents and Settings\LuBo\dwhelper
2008-03-21 00:23 . 2008-03-21 00:23 <DIR> d-------- C:\Program Files\MTA San Andreas
2008-03-14 13:53 . 2008-03-14 14:04 <DIR> d-------- C:\Program Files\MMGame
2008-03-14 13:53 . 2008-03-14 14:29 <DIR> d-------- C:\Program Files\GTA - Vice-City Millennium
2008-03-13 19:15 . 2008-03-13 19:16 <DIR> d-------- C:\Program Files\ACW
2008-03-13 19:07 . 2008-03-13 19:07 <DIR> d-------- C:\Program Files\Hamachi
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-09 10:40 --------- d-----w C:\Documents and Settings\LuBo\Application Data\Skype
2008-04-09 10:35 --------- d-----w C:\Documents and Settings\LuBo\Application Data\skypePM
2008-04-09 10:34 --------- d-----w C:\Documents and Settings\LuBo\Application Data\DMCache
2008-04-08 18:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\BOC425
2008-04-08 17:45 --------- d-----w C:\Documents and Settings\LuBo\Application Data\Spyware Terminator
2008-04-08 17:38 --------- d-----w C:\Program Files\Spyware Terminator
2008-04-08 17:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-04-08 10:51 --------- d-----w C:\Program Files\WinClamAVShield
2008-04-08 03:36 --------- d-----w C:\Program Files\PowerISO
2008-04-07 23:23 --------- d-----w C:\Program Files\Steam
2008-04-07 18:12 --------- d-----w C:\Documents and Settings\LuBo\Application Data\LimeWire
2008-04-06 15:07 --------- d-----w C:\Program Files\Winamp
2008-03-31 01:50 --------- d-----w C:\Documents and Settings\LuBo\Application Data\Video DVD Maker PRO
2008-03-30 16:57 --------- d-----w C:\Program Files\SpywareBlaster
2008-03-30 16:51 --------- d-----w C:\Program Files\SpywareGuard
2008-03-30 05:12 --------- d-----w C:\Program Files\SwiftSwitch
2008-03-26 05:25 --------- d-----w C:\Program Files\Dictionary
2008-03-19 23:34 --------- d-----w C:\Program Files\Java
2008-03-17 23:53 --------- d-----w C:\Documents and Settings\LuBo\Application Data\Hamachi
2008-03-13 23:11 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-03-12 23:03 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-08 15:18 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-03-08 15:17 --------- d-----w C:\Program Files\Common Files\Skype
2008-03-02 18:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-01 12:50 138,752 ----a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-02-26 21:38 --------- d-----w C:\Program Files\SopCast
2008-02-25 19:03 --------- d-----w C:\Program Files\ZD Soft
2008-02-24 00:14 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-23 23:26 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-02-13 00:52 --------- d-----w C:\Documents and Settings\LuBo\Application Data\DivX
2008-01-13 19:08 20 ----a-w C:\sccfg.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F11B882E-0A28-4E95-AF16-D0D3E56EA20F}]
C:\WINDOWS\system32\fccaYsSi.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"CursorXP"="C:\Program Files\CursorXP\CursorXP.exe" [2003-03-01 17:25 138240]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 12:28 139264]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2007-11-18 19:55 920064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Logitech Utility"="Logi_MwX.Exe" [2003-03-04 05:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"LogonStudio"="C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" [2002-09-03 19:38 987187]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 03:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 17:33 563984]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-05-16 12:58 213936]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 20:20 866584]
"BOC-425"="C:\PROGRA~1\Comodo\CBOClean\BOC425.exe" [2007-08-08 20:49 338432]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\CRavgas.exe" [2007-09-25 17:31 6731312]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 13:35 90112]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46 57344]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-03-01 08:50 2957824]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-02-29 18:31 866384]
"MRT"="C:\WINDOWS\system32\MRT.exe" [2007-09-05 19:50 17474680]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
FlexType 2K.lnk - C:\WINDOWS\Datecs\Flex2K.exe [2007-11-17 12:50:23 151552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\System32\\logonuiX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtrOgde]
awtrOgde.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll 2008-01-29 00:16 229376 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger Agent.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^LuBo^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\LuBo\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^LuBo^Start Menu^Programs^Startup^SpywareGuard.lnk]
path=C:\Documents and Settings\LuBo\Start Menu\Programs\Startup\SpywareGuard.lnk
backup=C:\WINDOWS\pss\SpywareGuard.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2005-12-10 10:57 133016 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyLinkAdvisor]
--a------ 2007-03-15 19:16 454784 C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-05-12 00:12 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD08]
--a------ 2005-06-01 12:35 49152 C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 2007-11-18 19:55 920064 C:\Program Files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-11-15 14:11 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
--a------ 2007-11-17 12:22 32768 C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
--a------ 2007-10-25 17:37 2178832 C:\Program Files\Logitech\QuickCam\Quickcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideo[inspector]]
C:\Program Files\Logitech\Video\InstallHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 17:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2006-05-20 06:13 188416 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-11-15 00:43 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-02-01 18:22 21898024 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2005-10-26 17:17 159744 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
--a------ 2008-03-01 08:50 2957824 C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-03-28 20:46 1271032 C:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TRIXX]
--a------ 2005-08-16 07:18 9576448 C:\Program Files\TRIXX\TRIXX.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\BitLord\\BitLord.exe"=
"C:\\Program Files\\Steam\\SteamApps\\razor4444\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Steam\\SteamApps\\razor4444\\half-life 2 deathmatch\\hl2.exe"=
"C:\\Program Files\\Steam\\SteamApps\\razor4444\\day of defeat source\\hl2.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"C:\\Program Files\\SwiftKit\\SwiftKit.exe"=
"C:\\Program Files\\SwiftSwitch\\SwiftSwitch.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-03-01 08:50]
R1 TRIXX;TRIXX;C:\Program Files\TRIXX\TRIXXDriver.sys [2005-08-16 07:17]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 06:29]
R3 n558;N558 Bluetooth USB Filter Driver;C:\WINDOWS\system32\Drivers\n558.sys [2007-08-15 08:27]
S3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-12-09 16:37]
S3 MSSQL$SONY_MEDIAMGR2;SQL Server (SONY_MEDIAMGR2);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSONY_MEDIAMGR2 []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\Setup.exe -auto
.
Contents of the 'Scheduled Tasks' folder
"2008-04-02 14:56:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-09 10:56:29 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-09 06:54:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\newdll.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Comodo\CBOClean\BOCORE.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\dumprep.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2008-04-09 7:00:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-09 11:00:22
Pre-Run: 3,201,789,952 bytes free
Post-Run: 3,071,561,728 bytes free
.
2008-04-09 02:03:11 --- E O F ---