ComboFix 09-12-31.06 - Crosser 12/31/2009 15:46:23.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.587 [GMT -8:00]
Running from: c:\documents and settings\Crosser\Desktop\Combo-Fix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\Crosser\Local Settings\Application Data\eiyolp
c:\documents and settings\Crosser\Local Settings\Application Data\eiyolp\xvypsysguard.exe
c:\documents and settings\Roa\Local Settings\Application Data\fkkexu
c:\documents and settings\Roa\Local Settings\Application Data\fkkexu\riiisysguard.exe
c:\windows\kb913800.exe
c:\windows\system32\drivers\gxvxcuwpjtxhbhdlyrqmltkmxmhlbppqlculq.sys
c:\windows\system32\drivers\gxvxcwyjkydvrodtfsqrucjcxjkmsbituchyf.sys
c:\windows\system32\drivers\gxvxcxrlnmsbnrjbpxesvxbfamtnopxmoysft.sys
c:\windows\system32\drivers\gxvxcxumkbpxnmwrriltxpylnberrngemqxfs.sys
c:\windows\system32\drivers\gxvxcykvpppmkpfvrbnyauqbuxymetadativl.sys
c:\windows\system32\drivers\gxvxcyxurrvkbsivielesixrerxkwnsftymeh.sys
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxcmoqxihovbnriqsiwwbdaibardlyxeoaf.dll
D:\autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gxvxcserv.sys
-------\Legacy_gxvxcserv.sys
((((((((((((((((((((((((( Files Created from 2009-12-01 to 2010-01-01 )))))))))))))))))))))))))))))))
.
2009-12-31 22:37 . 2009-12-30 22:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-31 22:37 . 2009-12-31 22:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-31 22:37 . 2009-12-31 22:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-31 22:37 . 2009-12-30 22:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-31 21:35 . 2009-12-31 21:35 -------- d-----w- c:\documents and settings\Crosser\Local Settings\Application Data\Conduit
2009-12-31 21:19 . 2009-12-31 21:19 -------- d-----w- c:\program files\TrendMicro
2009-12-31 20:49 . 2009-12-31 20:52 -------- d-----w- c:\documents and settings\Guest\Application Data\Azureus
2009-12-31 04:18 . 2009-12-31 04:18 -------- d-----w- c:\documents and settings\Guest\Application Data\vlc
2009-12-31 03:10 . 2009-12-31 22:22 -------- d-----w- c:\documents and settings\Crosser\Local Settings\Application Data\FearFM
2009-12-31 03:05 . 2009-12-31 03:05 -------- dc----w- c:\windows\system32\DRVSTORE
2009-12-28 08:24 . 2009-12-28 08:24 -------- d-----w- c:\documents and settings\Crosser\Application Data\acccore
2009-12-28 08:24 . 2009-12-28 08:24 -------- d-----w- c:\documents and settings\Crosser\Local Settings\Application Data\AOL OCP
2009-12-28 08:24 . 2009-12-28 08:24 -------- d-----w- c:\documents and settings\Crosser\Local Settings\Application Data\AOL
2009-12-28 08:24 . 2009-12-28 08:24 -------- d-----w- c:\documents and settings\Crosser\Local Settings\Application Data\Mozilla
2009-12-28 07:55 . 2009-12-28 07:55 28648 ----a-w- c:\documents and settings\Crosser\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-28 07:54 . 2009-12-28 08:22 -------- d-----w- c:\documents and settings\Crosser\Application Data\Apple Computer
2009-12-28 00:15 . 2009-12-28 00:15 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Mozilla
2009-12-15 01:01 . 2009-12-15 01:01 28648 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-15 01:01 . 2009-12-15 01:01 -------- d-----w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment
2009-12-15 01:01 . 2009-12-15 01:01 -------- d-----w- c:\documents and settings\Guest\Application Data\InstallShield Installation Information
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-31 23:58 . 2009-02-13 02:23 -------- d-----w- c:\program files\Symantec AntiVirus
2009-12-31 21:19 . 2009-12-31 21:19 388096 ----a-r- c:\documents and settings\Crosser\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2009-12-31 17:42 . 2009-03-05 00:21 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-12-31 03:06 . 2009-07-07 22:13 -------- d-----w- c:\documents and settings\Guest\Application Data\Apple Computer
2009-12-31 02:58 . 2009-08-27 08:17 -------- d-----w- c:\program files\VirtualDJ
2009-12-31 02:50 . 2009-07-07 22:13 664 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\d3d9caps.tmp
2009-12-29 04:35 . 2009-12-15 01:02 819880 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankB\WizardLauncher.exe
2009-12-29 04:35 . 2009-12-15 01:01 819880 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankA\WizardLauncher.exe
2009-12-29 04:35 . 2009-12-15 01:02 73728 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankB\PatchClientUIRsrc-En.dll
2009-12-29 04:35 . 2009-12-15 01:01 73728 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankA\PatchClientUIRsrc-En.dll
2009-12-29 04:35 . 2009-12-15 01:02 39424 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankB\ConfiguratorResEnglish.dll
2009-12-29 04:35 . 2009-12-15 01:02 103080 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankB\Configurator.exe
2009-12-29 04:35 . 2009-12-15 01:01 39424 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankA\ConfiguratorResEnglish.dll
2009-12-29 04:35 . 2009-12-15 01:01 103080 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankA\Configurator.exe
2009-12-27 20:05 . 2009-03-06 03:50 -------- d-----w- c:\documents and settings\Roa\Application Data\LimeWire
2009-12-18 03:16 . 2009-11-24 01:16 79488 ----a-w- c:\documents and settings\Roa\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-15 01:09 . 2009-12-15 01:09 449536 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Data\GameData\ZoneData\_Shared\WorldData\Sound\Miles72a\mss32.dll
2009-12-15 01:09 . 2009-12-15 01:09 389120 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Data\GameData\ZoneData\_Shared\WorldData\Sound\Miles\mss32.dll
2009-12-15 01:05 . 2009-12-15 01:05 59904 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\zlib1.dll
2009-12-15 01:05 . 2009-12-15 01:05 626688 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\msvcr80.dll
2009-12-15 01:05 . 2009-12-15 01:05 548864 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\msvcp80.dll
2009-12-15 01:05 . 2009-12-15 01:05 389120 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\mss32.dll
2009-12-15 01:04 . 2009-12-15 01:04 1101824 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\mfc80.dll
2009-12-15 01:04 . 2009-12-15 01:04 1645320 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\gdiplus.dll
2009-12-15 01:04 . 2009-12-15 01:04 1045128 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\dbghelp.dll
2009-12-15 01:04 . 2009-12-15 01:04 2414360 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\d3dx9_31.dll
2009-12-15 01:04 . 2009-12-15 01:04 16429736 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\WizardGraphicalClient.exe
2009-12-15 01:03 . 2009-12-15 01:03 135168 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\StringTableEditorMFC.dll
2009-12-15 01:03 . 2009-12-15 01:03 2 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\PropertyClassSystem.dll
2009-12-15 01:03 . 2009-12-15 01:03 73728 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\PatchClientUIRsrc-En.dll
2009-12-15 01:03 . 2009-12-15 01:03 49152 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\MG_Shockalock.dll
2009-12-15 01:03 . 2009-12-15 01:03 40960 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\MG_PotionMotion.dll
2009-12-15 01:03 . 2009-12-15 01:03 53248 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\MG_HotShots.dll
2009-12-15 01:03 . 2009-12-15 01:03 94208 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\MG_Dueling_Diego.dll
2009-12-15 01:03 . 2009-12-15 01:03 24576 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\MG_Concentration.dll
2009-12-15 01:03 . 2009-12-15 01:03 49152 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\MG_ChooChooZoo.dll
2009-12-15 01:03 . 2009-12-15 01:03 2 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\KIPlatformWebService.dll
2009-12-15 01:02 . 2009-12-15 01:02 2 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\KIPlatformDb.dll
2009-12-15 01:02 . 2009-12-15 01:02 2 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\KIHousingServer.dll
2009-12-15 01:02 . 2009-12-15 01:02 2 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Bin\KIDatabaseMySQLC.dll
2009-12-14 07:02 . 2009-12-15 01:01 59904 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankA\zlib1.dll
2009-12-14 07:02 . 2009-12-15 01:01 37032 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\Wizard101.exe
2009-12-14 07:02 . 2009-12-15 01:02 495616 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankB\SkinCrafterDll.dll
2009-12-14 07:02 . 2009-12-15 01:02 207872 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankB\patchw32.dll
2009-12-14 07:02 . 2009-12-15 01:02 1645320 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankB\gdiplus.dll
2009-12-14 07:02 . 2009-12-15 01:01 495616 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankA\SkinCrafterDll.dll
2009-12-14 07:02 . 2009-12-15 01:01 207872 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankA\patchw32.dll
2009-12-14 07:02 . 2009-12-15 01:01 1645320 ----a-w- c:\documents and settings\Guest\Application Data\KingsIsle Entertainment\Wizard101\PatchClient\BankA\gdiplus.dll
2009-12-11 03:44 . 2009-03-05 00:39 -------- d-----w- c:\program files\Vuze
2009-12-11 03:44 . 2009-03-05 00:41 -------- d-----w- c:\documents and settings\Roa\Application Data\Azureus
2009-12-11 00:35 . 2009-04-20 00:49 10686001 ----a-w- c:\documents and settings\Roa\Application Data\Azureus\plugins\azump\mplayer.exe
2009-11-28 02:07 . 2009-03-05 00:19 -------- d-----w- c:\program files\Safari
2009-11-28 02:04 . 2009-11-28 02:04 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-11-07 23:39 . 2009-03-05 00:47 -------- d-----w- c:\program files\LimeWire
2009-11-07 23:00 . 2009-11-07 22:59 -------- d-----w- c:\program files\iTunes
2009-11-07 22:59 . 2009-11-07 22:59 -------- d-----w- c:\program files\iPod
2009-11-07 22:59 . 2009-03-05 00:29 -------- d-----w- c:\program files\Common Files\Apple
2009-11-07 22:49 . 2009-11-07 22:49 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-07 23:14 . 2009-10-07 23:13 7621144 ---h--w- c:\documents and settings\Danilo\Application Data\mjusbsp\ar00000\upgrade.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2004-07-22 88361]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for ViewSonic\traybar.exe" [2007-08-20 774144]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
c:\documents and settings\Danilo\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\Roa\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
"WMConnectCDS"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/4/2009 4:29 PM 24652]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/28/2009 7:01 PM 102448]
S3 {439FAEC5-095A-43C2-9290A2A59C80A007};{439FAEC5-095A-43C2-9290A2A59C80A007};c:\windows\System32\svchost.exe -k netsvcs [8/3/2004 3:56 PM 14336]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/27/2006 8:33 PM 116464]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
{439FAEC5-095A-43C2-9290A2A59C80A007}
.
Contents of the 'Scheduled Tasks' folder
2009-12-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.myspace.com/mStart Page =
hxxp://www.myspace.com/FF - ProfilePath - c:\documents and settings\Crosser\Application Data\Mozilla\Firefox\Profiles\9584y075.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-qeqxngvr - c:\documents and settings\Crosser\Local Settings\Application Data\eiyolp\xvypsysguard.exe
AddRemove-FreeHDplay - c:\program files\FreeHDplay\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-31 16:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\{439FAEC5-095A-43C2-9290A2A59C80A007}]
"ServiceDll"="c:\docume~1\Crosser\LOCALS~1\Temp\45.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1492)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\AGRSMMSG.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2009-12-31 16:16:28 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-01 00:16
Pre-Run: 73,467,285,504 bytes free
Post-Run: 75,776,794,624 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 984308396920727CE7487868B85FA15D