ComboFix 09-07-26.03 - HungryMan 07/27/2009 15:30.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.682 [GMT -5:00]
Running from: c:\documents and settings\HungryMan\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\windows\Installer\285479.msi
c:\windows\system32\drivers\gxvxcltpdqbompjnklvdyiqhbqhvsngrowntj.sys
c:\windows\system32\drivers\gxvxcvxtlwhxymvkipjpypiemrsswutfmqepk.sys
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxcixdropnvuueqoeyarpsptmlqorvpqbgc.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gxvxcserv.sys
((((((((((((((((((((((((( Files Created from 2009-06-27 to 2009-07-27 )))))))))))))))))))))))))))))))
.
2009-07-27 19:57 . 2007-10-23 14:27 110592 ----a-w- c:\documents and settings\HungryMan\Application Data\U3\temp\cleanup.exe
2009-07-25 20:07 . 2009-07-25 20:08 -------- d-----w- c:\program files\CPU Thermometer
2009-07-19 16:31 . 2009-07-10 18:08 3403032 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-07-16 08:11 . 2009-07-16 08:11 -------- d-----w- c:\documents and settings\HungryMan\Local Settings\Application Data\Temp
2009-06-29 13:52 . 2009-06-29 13:51 2052376 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-06-28 20:32 . 2001-08-18 03:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-06-28 20:32 . 2008-04-14 10:42 159232 ----a-w- c:\windows\system32\ptpusd.dll
2009-06-28 20:32 . 2008-04-14 05:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2009-06-28 20:32 . 2008-04-14 05:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-06-28 20:30 . 2007-09-19 03:45 2053512 ----a-r- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_140002_1f34de\Setup.exe
2009-06-28 20:29 . 2007-09-19 03:45 2053512 ----a-r- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_140002_1e1e94\Setup.exe
2009-06-28 20:29 . 2009-06-28 20:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Kodak
2009-06-28 20:29 . 2009-06-28 20:29 114688 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$Registration\KodakCameraAPI_7.5.20.2.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-27 19:57 . 2003-01-17 05:03 -------- d-----w- c:\documents and settings\HungryMan\Application Data\U3
2009-07-10 18:08 . 2003-01-19 04:22 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-16 19:15 . 2009-05-04 01:22 22144 ----a-w- c:\documents and settings\HungryMan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-16 18:50 . 2003-01-19 04:22 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-16 14:36 . 2008-04-14 04:42 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2008-04-14 04:41 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-10 18:37 . 2003-01-19 03:41 -------- d-----w- c:\program files\Java
2009-06-10 18:36 . 2009-06-10 18:36 152576 ----a-w- c:\documents and settings\HungryMan\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-08 19:44 . 2003-01-19 03:32 -------- d-----w- c:\documents and settings\HungryMan\Application Data\BitTorrent
2009-06-03 19:09 . 2008-04-14 04:42 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-06-02 02:38 . 2009-06-02 02:22 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-02 02:38 . 2009-06-02 02:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-02 02:37 . 2009-06-02 01:26 -------- d-----w- c:\program files\Lavasoft
2009-06-02 01:33 . 2009-06-02 01:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-01 22:07 . 2009-06-01 21:44 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-01 21:17 . 2009-06-01 21:17 -------- d-----w- c:\documents and settings\All Users\Application Data\PCPitstop
2009-06-01 21:06 . 2009-06-01 19:01 -------- d-----w- c:\documents and settings\HungryMan\Application Data\IObit
2009-06-01 18:57 . 2009-06-01 18:56 -------- d-----w- c:\documents and settings\HungryMan\Application Data\AdwareBot
2009-06-01 17:43 . 2009-06-01 16:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-21 16:33 . 2003-01-19 04:21 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-07 15:32 . 2008-04-14 04:41 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-05 06:17 . 2009-05-05 06:17 249856 -c----w- c:\windows\Setup1.exe
2009-05-05 06:17 . 2009-05-05 06:17 73216 -c--a-w- c:\windows\ST6UNST.EXE
2009-05-05 05:59 . 2009-05-05 05:35 36063 -c--a-w- c:\windows\DIIUnin.dat
2009-05-05 05:58 . 2009-05-05 05:57 21840 ----atw- c:\windows\system32\SIntfNT.dll
2009-05-05 05:58 . 2009-05-05 05:57 17212 ----atw- c:\windows\system32\SIntf32.dll
2009-05-05 05:58 . 2009-05-05 05:57 12067 -c--atw- c:\windows\system32\SIntf16.dll
2009-05-05 05:35 . 2009-05-05 05:35 94208 -c--a-w- c:\windows\DIIUnin.exe
2009-05-05 05:35 . 2009-05-05 05:35 2829 -c--a-w- c:\windows\DIIUnin.pif
2009-05-04 01:30 . 2009-05-04 01:30 0 -c--a-w- c:\windows\nsreg.dat
2009-05-04 01:17 . 2009-05-04 01:17 152576 -c--a-w- c:\documents and settings\HungryMan\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-29 04:56 . 2008-04-14 04:42 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2008-04-14 04:41 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-22 14:32 . 2009-05-04 01:29 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="c:\documents and settings\HungryMan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-04 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2003-01-19 04:22 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/18/2003 11:22 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/18/2003 11:22 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [1/18/2003 11:21 PM 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/18/2003 11:21 PM 298776]
.
Contents of the 'Scheduled Tasks' folder
2009-07-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1060284298-1343024091-1003Core.job
- c:\documents and settings\HungryMan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-04 16:11]
2009-07-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1060284298-1343024091-1003UA.job
- c:\documents and settings\HungryMan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-04 16:11]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.kingsofchaos.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\documents and settings\HungryMan\Application Data\Mozilla\Firefox\Profiles\5qbfp0f8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.kingsofchaos.com/
FF - plugin: c:\documents and settings\HungryMan\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Adobe Reader 9.0\Reader\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-27 15:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(480)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-07-27 15:36
ComboFix-quarantined-files.txt 2009-07-27 20:36
Pre-Run: 22,954,262,528 bytes free
Post-Run: 23,181,934,592 bytes free
140 --- E O F --- 2009-07-15 05:04