Hi,
Ok - so i ran combofix...just so you know i ran combo fix without having a LAN cable plugged in as i was downloading/transferring using a USB stick, so before it was too late - windows recovery console couldnt be installed as i was not on the network...didn't want to interrupt the scan so i let it run without having WRC installed...anyway here is the log..let me know.
ComboFix 09-10-01.05 - navead bhatti 04/10/2009 10:46.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.450 [GMT 1:00]
Running from: c:\documents and settings\navead bhatti\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\equhaticof.inf
c:\documents and settings\All Users\Application Data\gibawy.reg
c:\documents and settings\All Users\Application Data\kivifowiwa.vbs
c:\documents and settings\All Users\Application Data\ufup.bat
c:\documents and settings\All Users\Application Data\ujyto.inf
c:\documents and settings\All Users\Documents\ovakezo.bat
c:\documents and settings\All Users\Documents\qenafibaxa.bat
c:\documents and settings\navead bhatti\Application Data\IUpd721
c:\documents and settings\navead bhatti\Application Data\IUpd721\Logs\scns.log
c:\documents and settings\navead bhatti\Cookies\ebulebozil.dat
c:\documents and settings\navead bhatti\Cookies\ejacy.dl
c:\documents and settings\navead bhatti\Cookies\lyrub._dl
c:\documents and settings\navead bhatti\Cookies\okirimo.scr
c:\documents and settings\navead bhatti\Cookies\sesery.pif
c:\documents and settings\navead bhatti\Local Settings\Application Data\egydunehat.inf
c:\documents and settings\navead bhatti\Local Settings\Application Data\eqofyqide.bat
c:\documents and settings\navead bhatti\Local Settings\Temporary Internet Files\jydafofu.bin
c:\documents and settings\navead bhatti\Local Settings\Temporary Internet Files\lisixige.reg
c:\documents and settings\navead bhatti\Local Settings\Temporary Internet Files\loterivalo.reg
c:\documents and settings\navead bhatti\Local Settings\Temporary Internet Files\miqyqik.vbs
c:\documents and settings\navead bhatti\Local Settings\Temporary Internet Files\muxifoci.bin
c:\documents and settings\navead bhatti\Local Settings\Temporary Internet Files\ociquz.pif
c:\documents and settings\navead bhatti\Local Settings\Temporary Internet Files\oturu._dl
c:\documents and settings\navead bhatti\Local Settings\Temporary Internet Files\ugihopak.scr
c:\documents and settings\navead bhatti\Local Settings\Temporary Internet Files\xore.db
C:\HijackThis.exe
C:\p2hhr.bat
c:\windows\evofin.bat
c:\windows\imapapeq.reg
c:\windows\noladapu.vbs
c:\windows\qecesege.reg
c:\windows\riqeryvaw.scr
c:\windows\run.log
c:\windows\system32\drivers\SKYNETtyqcbnat.sys
c:\windows\system32\drivers\UACvsbftkpjqw.sys
c:\windows\system32\SKYNETklwqggkr.dat
c:\windows\system32\SKYNETniddfoxw.dll
c:\windows\system32\SKYNETyrplnnkb.dll
c:\windows\system32\SKYNETyusiadul.dat
c:\windows\system32\UACasawfdbenb.dll
c:\windows\system32\UACchowxafnks.dll
c:\windows\system32\UACievxrsiwmv.dat
c:\windows\system32\UACmcetrqqycb.dll
c:\windows\system32\UACndbavhdmlp.db
c:\windows\system32\UACqnakijjwxb.dll
c:\windows\system32\UACrvtsapetqa.log
c:\windows\system32\UACxdbuxovanw.dll
c:\windows\UA000031.DLL
c:\windows\UA000035.DLL
c:\windows\xykyfen.vbs
c:\windows\ynh.dx
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SKYNETrpqkyodu
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_SKYNETrpqkyodu
((((((((((((((((((((((((( Files Created from 2009-09-04 to 2009-10-04 )))))))))))))))))))))))))))))))
.
2009-10-02 17:13 . 2009-10-02 17:13 -------- d-----w- c:\documents and settings\navead bhatti\Application Data\Malwarebytes
2009-10-02 17:11 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-02 17:11 . 2009-10-02 17:13 -------- d-----w- c:\program files\set
2009-10-02 17:11 . 2009-10-02 17:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-02 17:11 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-29 17:44 . 2009-09-29 17:44 -------- d-----w- c:\program files\TJH
2009-09-09 10:06 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-28 21:10 . 2006-06-11 21:14 -------- d-----w- c:\documents and settings\navead bhatti\Application Data\Lavasoft
2009-09-28 21:06 . 2009-06-19 17:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-28 21:04 . 2006-05-05 18:36 -------- d-----w- c:\program files\Dl_cats
2009-09-17 12:03 . 2009-06-19 16:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-13 11:19 . 2006-05-02 20:26 -------- d-----w- c:\program files\Java
2009-09-09 21:54 . 2009-03-13 01:20 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-28 19:33 . 2009-06-19 17:03 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-28 19:33 . 2009-06-19 17:03 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-28 19:33 . 2009-06-19 17:03 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-11 17:00 . 2009-08-11 17:00 17622 ----a-w- c:\windows\imonihunuj.bin
2009-08-11 17:00 . 2009-08-11 17:00 13987 ----a-w- c:\program files\Common Files\adodi.pif
2009-08-11 17:00 . 2009-08-11 17:00 13038 ----a-w- c:\windows\system32\cexip.pif
2009-08-11 17:00 . 2009-08-11 17:00 12786 ----a-w- c:\windows\system32\kejowaz.bin
2009-08-11 17:00 . 2009-08-11 17:00 11740 ----a-w- c:\program files\Common Files\feguvalyh.dat
2009-08-11 17:00 . 2009-08-11 17:00 10728 ----a-w- c:\windows\favukiwe.sys
2009-08-10 16:13 . 2009-02-23 23:37 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2009-08-09 11:27 . 2009-08-09 11:27 18673 ----a-w- c:\documents and settings\All Users\Application Data\apinuga.com
2009-08-09 11:27 . 2009-08-09 11:27 17810 ----a-w- c:\documents and settings\All Users\Application Data\usolix.dat
2009-08-09 11:27 . 2009-08-09 11:27 17059 ----a-w- c:\windows\system32\dysadub.dat
2009-08-09 11:27 . 2009-08-09 11:27 16025 ----a-w- c:\program files\Common Files\emaq.dl
2009-08-09 11:27 . 2009-08-09 11:27 12471 ----a-w- c:\documents and settings\All Users\Application Data\gizuwox.dat
2009-08-09 11:27 . 2009-08-09 11:27 11899 ----a-w- c:\windows\system32\yzasim.com
2009-08-09 11:27 . 2009-08-09 11:27 11557 ----a-w- c:\windows\system32\olitah.bin
2009-08-09 11:27 . 2009-08-09 11:27 17929 ----a-w- c:\documents and settings\navead bhatti\Local Settings\Application Data\apux.dll
2009-08-09 11:27 . 2009-08-09 11:27 15326 ----a-w- c:\program files\Common Files\rokyceluc.pif
2009-08-09 11:27 . 2009-08-09 11:27 13878 ----a-w- c:\windows\edahedezeg.bin
2009-08-09 11:27 . 2009-08-09 11:27 13400 ----a-w- c:\documents and settings\All Users\Application Data\ekexe.sys
2009-08-09 11:15 . 2009-06-19 17:02 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-09 10:57 . 2006-05-05 18:21 95560 ----a-w- c:\documents and settings\navead bhatti\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-08 12:16 . 2009-08-08 12:16 15407 ----a-w- c:\windows\system32\sopocem.dat
2009-08-08 12:16 . 2009-08-08 12:16 14252 ----a-w- c:\program files\Common Files\axat.dll
2009-08-08 12:16 . 2009-08-08 12:16 12319 ----a-w- c:\documents and settings\navead bhatti\Local Settings\Application Data\umijo.scr
2009-08-06 23:21 . 2009-06-19 16:49 -------- d-----w- c:\program files\MSBuild
2009-08-06 23:21 . 2009-08-06 23:21 -------- d-----w- c:\program files\Reference Assemblies
2009-08-05 09:01 . 2004-08-10 11:51 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-25 04:23 . 2008-12-09 22:30 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2004-08-10 11:50 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 22:43 . 2004-08-10 11:51 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2008-04-05 22:10 . 2009-06-19 16:50 262144 ----a-w- c:\program files\Uninstall Spy Blocker.dll
2007-07-04 19:24 . 2007-07-04 19:25 787968 ----a-w- c:\program files\Copy of MultipleChoiceTemplate qwizdom.ppt
2007-07-01 12:52 . 2007-07-01 12:52 329128 ----a-w- c:\program files\ripsetup.exe
2006-11-17 00:13 . 2006-05-07 23:58 56 --sh--r- c:\windows\system32\184C950EED.sys
2008-03-15 15:01 . 2006-05-06 13:32 88 --sh--r- c:\windows\system32\ED0E954C18.sys
2008-03-15 15:01 . 2006-05-06 13:32 6424 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DrvMon.exe"="c:\windows\system32\DrvMon.exe" [2004-11-29 53248]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2005-08-18 307200]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080]
"Sunkist2k"="c:\program files\Trust_CR-1200_16-in-1_USB2_CARD_READER\shwicon2k.exe" [2005-06-29 143360]
"AVFX Engine"="c:\program files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-08-16 24576]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-18 198160]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-13 73728]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\set\set.exe" [2009-09-10 1312080]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-22 339968]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-11-29 569405]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2006-3-26 257752]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 233472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 19:33 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SightSpeed\\SightSpeed.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"96:TCP"= 96:TCP:Express Invoice Web Server
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [19/06/2009 18:03 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [19/06/2009 18:03 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [19/06/2009 18:02 297752]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [13/03/2009 02:20 55152]
S2 dfbstc;dfbstc;\??\c:\windows\system32\drivers\zrxfjsbr.sys --> c:\windows\system32\drivers\zrxfjsbr.sys [?]
S2 eygzgw;Shell Driver;c:\windows\system32\svchost.exe -k netsvcs [10/08/2004 12:51 14336]
S2 ksorc;Universal Monitor;c:\windows\system32\svchost.exe -k netsvcs [10/08/2004 12:51 14336]
S2 lnuzuri;Manager Helper;c:\windows\system32\svchost.exe -k netsvcs [10/08/2004 12:51 14336]
S2 nrshspexf;Boot Manager;c:\windows\system32\svchost.exe -k netsvcs [10/08/2004 12:51 14336]
S3 ExpressInvoiceService;Express Invoice;c:\program files\NCH Software\ExpressInvoice\expressinvoice.exe [27/06/2009 17:56 1105924]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19:08 533360]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
eygzgw
ksorc
nrshspexf
lnuzuri
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.comuSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8mStart Page =
hxxp://www.google.comuInternet Connection Wizard,ShellNext =
hxxp://www.hackerwatch.org/probe/IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
.
- - - - ORPHANS REMOVED - - - -
Notify-c00EF55C - c00EF55C.mat
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-04 10:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\eygzgw]
"ServiceDll"="c:\windows\system32\imypx.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ksorc]
"ServiceDll"="c:\windows\system32\imypx.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lnuzuri]
"ServiceDll"="c:\windows\system32\imypx.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nrshspexf]
"ServiceDll"="c:\program files\Internet Explorer\imypx.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2456)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\dlcccoms.exe
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
c:\program files\Windows Desktop Search\WindowsSearchIndexer.exe
.
**************************************************************************
.
Completion time: 2009-10-04 10:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-04 09:59
Pre-Run: 221,230,186,496 bytes free
Post-Run: 222,290,972,672 bytes free
266 --- E O F --- 2009-09-09 21:47