Here's the report:
ComboFix 09-10-24.01 - Windows XP 10/24/2009 22:17.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.562 [GMT -7:00]
Running from: c:\documents and settings\Windows XP\Desktop\kahdah.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
AV: Norton 360 Premier Edition *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 Premier Edition *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Windows XP\Application Data\.#
c:\documents and settings\Windows XP\Application Data\.#\MBX@B04@93CFC0.###
c:\documents and settings\Windows XP\Application Data\.#\MBX@B04@93E7D0.###
c:\documents and settings\Windows XP\Application Data\.#\MBX@B04@93E880.###
c:\documents and settings\Windows XP\Application Data\.#\MBX@B04@93EAE0.###
c:\documents and settings\Windows XP\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk
c:\documents and settings\Windows XP\Local Settings\Temporary Internet Files\awesu.dll
c:\documents and settings\Windows XP\Local Settings\Temporary Internet Files\jehi.lib
c:\documents and settings\Windows XP\Local Settings\Temporary Internet Files\savy.sys
C:\p2hhr.bat
c:\program files\Common Files\adypefel.bat
c:\program files\Common Files\ujajadyge.reg
c:\program files\Dealio Toolbar
c:\program files\Dealio Toolbar\config.ini
c:\program files\Dealio Toolbar\DealioToolbarIE.dll
c:\program files\Dealio Toolbar\Res\amazon.gif
c:\program files\Dealio Toolbar\Res\apple.gif
c:\program files\Dealio Toolbar\Res\barnes.gif
c:\program files\Dealio Toolbar\Res\bestbuy.gif
c:\program files\Dealio Toolbar\Res\dealio_logo.gif
c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\Res\ebay.gif
c:\program files\Dealio Toolbar\Res\icon_settings.gif
c:\program files\Dealio Toolbar\Res\macys.gif
c:\program files\Dealio Toolbar\Res\newegg.gif
c:\program files\Dealio Toolbar\Res\overstock.gif
c:\program files\Dealio Toolbar\Res\search-button-hover.gif
c:\program files\Dealio Toolbar\Res\search-button.gif
c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif
c:\program files\Dealio Toolbar\Res\search-chevron.gif
c:\program files\Dealio Toolbar\Res\search_amazon.gif
c:\program files\Dealio Toolbar\Res\search_dealio.gif
c:\program files\Dealio Toolbar\Res\search_ebay.gif
c:\program files\Dealio Toolbar\Res\search_yahoo.gif
c:\program files\Dealio Toolbar\Res\separator.gif
c:\program files\Dealio Toolbar\Res\target.gif
c:\program files\Dealio Toolbar\Res\walmart.gif
c:\program files\Dealio Toolbar\Res\widgets.xml
c:\program files\Dealio Toolbar\SearchSettings.dll
c:\program files\Dealio Toolbar\SearchSettings.exe
c:\program files\Dealio Toolbar\SearchSettingsRes409.dll
c:\program files\Dealio Toolbar\sscfg.ini
c:\program files\Dealio Toolbar\WidgiHelper.exe
c:\windows\avicahuhi.bat
c:\windows\ppp3.dat
c:\windows\ppp4.dat
c:\windows\ryjylymexo.scr
c:\windows\system32\auwpmcsg.ini
c:\windows\system32\bennuar.old
c:\windows\system32\dumphive.exe
c:\windows\system32\hidjhyhh.ini
c:\windows\system32\HRtsDfhk.ini
c:\windows\system32\HRtsDfhk.ini2
c:\windows\system32\IEDFix.exe
c:\windows\system32\ieupdates.exe.tmp
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\jihkknpo.ini
c:\windows\system32\jihkknpo.ini2
c:\windows\system32\Process.exe
c:\windows\system32\siwxjjsb.ini
c:\windows\system32\sonhelp.htm
c:\windows\system32\SrchSTS.exe
c:\windows\system32\sysnet.dat
c:\windows\system32\tapi.nfo
c:\windows\system32\tcmahain.ini
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\VyIilnnn.ini
c:\windows\system32\VyIilnnn.ini2
c:\windows\system32\wispex.html
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-09-25 to 2009-10-25 )))))))))))))))))))))))))))))))
.
2009-10-25 05:38 . 2009-10-25 05:38 -------- d-----w- C:\$AVG
2009-10-24 16:44 . 2009-10-24 16:44 -------- d-----w- c:\documents and settings\Windows XP\Application Data\AVG8
2009-10-24 16:23 . 2009-10-24 16:23 -------- d-----w- c:\program files\Spyware Doctor
2009-10-24 16:23 . 2009-10-24 16:23 -------- d-----w- c:\documents and settings\Windows XP\Application Data\PC Tools
2009-10-21 02:21 . 2009-10-22 23:21 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-10-21 02:21 . 2009-10-21 02:21 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-10-21 00:54 . 2009-10-21 00:54 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-10-21 00:52 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-10-21 00:50 . 2009-10-21 00:50 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-21 00:50 . 2009-10-21 00:50 -------- d-----w- c:\program files\Lavasoft
2009-10-21 00:50 . 2009-10-21 00:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-20 04:01 . 2009-10-20 04:01 -------- d-----w- c:\documents and settings\Windows XP\Local Settings\Application Data\Threat Expert
2009-10-18 04:14 . 2009-10-18 04:14 -------- d-----w- c:\program files\VALVe
2009-10-17 00:09 . 2009-10-17 00:09 291328 ----a-w- C:\cmjb6k4l.exe
2009-10-06 14:24 . 2009-10-06 14:24 -------- d-----w- C:\Sega
2009-10-05 00:38 . 2009-10-05 00:40 -------- d-----w- c:\program files\Guilty Gear ISUKA
2009-09-27 23:50 . 2009-10-18 23:12 -------- d-----w- c:\program files\Steam
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-25 05:11 . 2009-04-05 17:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-25 05:11 . 2009-04-05 17:38 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-10-24 19:59 . 2008-08-25 03:14 -------- d-----w- c:\program files\lx_cats
2009-10-24 16:23 . 2009-09-07 17:52 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-10-24 16:20 . 2008-11-02 20:45 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-22 23:22 . 2009-09-10 03:06 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-22 23:21 . 2009-09-10 03:06 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-21 02:22 . 2009-09-16 00:19 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-10-21 02:21 . 2009-09-10 03:06 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-10-21 02:21 . 2009-09-10 03:06 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-21 02:21 . 2009-09-10 01:57 -------- d-----w- c:\program files\AVG
2009-10-21 01:06 . 2008-07-02 23:26 -------- d-----w- c:\program files\Google
2009-10-21 00:55 . 2002-01-04 03:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-21 00:35 . 2002-01-04 03:49 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-21 00:33 . 2009-09-23 15:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-20 23:13 . 2009-05-06 00:56 -------- d-----w- c:\program files\Acoustica Mixcraft 4
2009-10-18 23:16 . 2009-06-13 06:21 -------- d-----w- c:\program files\Counter-Strike 1.6 V40
2009-10-03 15:29 . 2009-09-06 05:26 -------- d-----w- c:\program files\RegCure
2009-09-23 16:02 . 2009-09-13 20:46 -------- d-----w- c:\program files\Download Direct
2009-09-23 15:55 . 2009-09-23 15:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-20 00:48 . 2002-01-04 04:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-20 00:29 . 2009-09-20 00:29 -------- d-----w- c:\program files\Ubisoft
2009-09-18 14:16 . 2009-09-18 14:16 -------- d-----w- c:\documents and settings\Windows XP\Application Data\Search Settings
2009-09-18 14:16 . 2009-09-18 14:16 -------- d-----w- c:\documents and settings\Windows XP\Application Data\Dealio
2009-09-18 12:10 . 2009-09-18 12:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-09-16 21:35 . 2009-08-22 06:14 25 ----a-w- c:\windows\popcinfot.dat
2009-09-16 21:35 . 2009-08-22 03:03 -------- d-----w- c:\program files\Plants Vs Zombies
2009-09-13 20:37 . 2002-01-03 10:31 92384 ----a-w- c:\documents and settings\Windows XP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-10 23:42 . 2009-09-10 23:42 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-09-10 21:54 . 2009-09-23 15:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 21:53 . 2009-09-23 15:55 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-10 02:36 . 2009-03-14 04:01 -------- d-----w- c:\program files\Activision
2009-09-10 02:33 . 2008-07-05 05:46 -------- d-----w- c:\documents and settings\Windows XP\Application Data\Lavasoft
2009-09-10 02:30 . 2009-09-06 07:04 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-09-10 01:21 . 2009-09-10 01:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Gtek
2009-09-10 01:21 . 2009-09-10 01:21 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-09-09 04:46 . 2008-08-08 13:25 256 ----a-w- c:\windows\system32\pool.bin
2009-09-09 03:18 . 2009-09-09 02:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-09-09 03:18 . 2009-09-09 02:54 -------- d-----w- c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-09-09 02:51 . 2009-04-05 16:55 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-09-07 20:44 . 2009-08-14 00:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-06 21:40 . 2009-09-06 21:40 -------- d-----w- c:\program files\Trend Micro
2009-09-06 07:05 . 2009-09-06 07:05 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-09-06 07:04 . 2009-09-06 07:04 -------- d-----w- c:\program files\Common Files\iS3
2009-09-06 05:40 . 2009-09-06 05:40 -------- d-----w- c:\program files\ToniArts
2009-09-06 04:49 . 2009-09-06 04:47 -------- d-----w- c:\program files\SpyNoMore
2009-09-06 04:47 . 2009-09-06 04:47 1152 ----a-w- c:\windows\system32\windrv.sys
2009-09-06 04:47 . 2009-08-14 00:05 -------- d-----w- c:\documents and settings\Windows XP\Application Data\GetRightToGo
2009-09-06 03:48 . 2009-03-01 23:47 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-06 03:39 . 2009-09-06 03:39 687104 ----a-w- c:\windows\is-ENRAR.exe
2009-09-06 03:00 . 2009-09-06 03:00 17405 ----a-w- c:\documents and settings\Windows XP\Application Data\ejonyl.bin
2009-09-06 03:00 . 2009-09-06 03:00 15169 ----a-w- c:\documents and settings\Windows XP\Local Settings\Application Data\ezokilu.pif
2009-09-06 03:00 . 2009-09-06 03:00 14639 ----a-w- c:\documents and settings\Windows XP\Local Settings\Application Data\wirom.exe
2009-09-06 03:00 . 2009-09-06 03:00 12486 ----a-w- c:\documents and settings\Windows XP\Application Data\ecaf.scr
2009-09-06 03:00 . 2009-09-06 03:00 10915 ----a-w- c:\windows\system32\owokyhuqy.pif
2009-09-06 03:00 . 2009-09-06 03:00 10879 ----a-w- c:\program files\Common Files\jivak.dat
2009-09-06 00:27 . 2009-09-06 00:27 -------- d-----w- c:\program files\Sega
2009-09-02 00:49 . 2009-09-02 00:49 -------- d-----w- c:\program files\Common Files\NSV
2009-08-30 04:25 . 2009-08-16 02:49 255 ----a-w- c:\windows\PowerReg.dat
2009-08-30 04:24 . 2009-08-30 04:24 -------- d-----w- c:\program files\Hasbro Interactive
2009-08-30 04:24 . 2009-08-30 04:24 0 ----a-w- c:\windows\DXT1654.tmp
2009-08-30 04:24 . 2009-08-30 04:24 0 ----a-w- c:\windows\DXT1653.tmp
2009-08-30 04:24 . 2009-08-30 04:24 0 ----a-w- c:\windows\DXT1652.tmp
2009-08-30 04:24 . 2009-08-30 04:24 0 ----a-w- c:\windows\DXT1651.tmp
2009-08-30 04:24 . 2009-08-30 04:24 0 ----a-w- c:\windows\DXT1650.tmp
2009-08-30 04:24 . 2009-08-30 04:24 0 ----a-w- c:\windows\DXT164F.tmp
2009-08-30 04:24 . 2009-08-30 04:24 0 ----a-w- c:\windows\DXT164E.tmp
2009-08-30 04:24 . 2009-08-30 04:24 0 ----a-w- c:\windows\DXT164D.tmp
2009-08-23 00:21 . 2009-08-23 00:13 12265 ----a-w- c:\windows\scunin.dat
2009-08-23 00:13 . 2009-08-23 00:13 967 ----a-w- c:\windows\ScUnin.pif
2009-08-23 00:13 . 2009-08-23 00:13 68096 ----a-w- c:\windows\ScUnin.exe
2009-08-17 01:43 . 2008-12-31 23:23 1014 ----a-w- c:\windows\eReg.dat
2009-08-16 02:49 . 2009-08-16 02:43 905 ----a-w- c:\program files\uninstal.log
2009-08-05 09:01 . 2008-04-14 12:42 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-05-31 20:49 . 2009-05-31 20:49 25 ----a-w- c:\program files\popcinfot.dat
2006-12-13 03:12 . 2002-01-04 04:25 66648 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2006-12-13 03:12 . 2002-01-04 04:25 54352 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2006-12-13 03:12 . 2002-01-04 04:25 34928 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2006-12-13 03:12 . 2002-01-04 04:25 46696 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2006-12-13 03:12 . 2002-01-04 04:25 172120 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2008-09-07 05:01 . 2008-09-07 04:38 56 --sh--r- c:\windows\system32\41E010771D.sys
2008-09-07 05:01 . 2008-09-07 04:38 848 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-18 19:28 1115392 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1115392]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1115392]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-16 454784]
"L07AXLRD_59744406"="c:\program files\Microsoft Student\Microsoft Student with Encarta Premium 2007 DVD\EDICT.EXE" [2006-06-10 351000]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-04-01 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-04-01 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-04-01 114688]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-09-24 49152]
"lxcymon.exe"="c:\program files\Lexmark 3400 Series\lxcymon.exe" [2007-06-25 291504]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-10-04 28672]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-21 177472]
"SNM"="c:\program files\SpyNoMore\SNM.exe" [2007-11-15 1212368]
"LXCYCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [2006-11-21 106496]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-10-22 2010904]
"WINDVDPatch"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2002-02-08 40960]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]
c:\documents and settings\Windows XP\Start Menu\Programs\Startup\
Rainlendar.lnk - c:\program files\Rainlendar\Rainlendar.exe [2006-1-21 118784]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-9-24 282624]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-05 14:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-21 02:21 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=c:\windows\pss\Desktop Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NOD32FiXTemDono"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\NovaLogic\\Delta Force Black Hawk Down\\dfbhd.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\WINDOWS\\system32\\lxcycoms.exe"=
"c:\\Sierra\\Half-Life\\hl.exe"=
"c:\\Program Files\\UnrealTournament\\System\\UnrealTournament.exe"=
"c:\\Sierra\\Half-Life\\hltv.exe"=
"c:\\Sierra\\Half-Life\\hlds.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [10/20/2009 7:21 PM 161800]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [10/20/2009 5:52 PM 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/9/2009 8:06 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/9/2009 8:06 PM 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2/17/2009 11:43 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/17/2009 11:43 AM 74480]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [10/20/2009 7:21 PM 285392]
R2 lxcy_device;lxcy_device;c:\windows\system32\lxcycoms.exe -service --> c:\windows\system32\lxcycoms.exe -service [?]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [5/24/2009 9:50 PM 234888]
S2 gupdate1ca51e87f4c1cbc;Google Update Service (gupdate1ca51e87f4c1cbc);c:\program files\Google\Update\GoogleUpdate.exe [10/20/2009 5:50 PM 133104]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 4:17 AM 1169232]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/17/2009 11:43 AM 7408]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{AAAAAAAA-IWE2-R26D-0I80-XP2V372A0343}]
c:\documents and settings\Windows XP\Desktop\Youtube.exe Restart
.
Contents of the 'Scheduled Tasks' folder
2009-10-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:06]
2009-10-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-21 00:50]
2009-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-21 00:50]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.daemon-search.com/startpage
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
LSP: xfire_lsp_10650.dll
Trusted Zone: aol.com\free
Trusted Zone: nintendo.com\club
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
FF - ProfilePath - c:\documents and settings\Windows XP\Application Data\Mozilla\Firefox\Profiles\f0buqek6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2031308&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - DigitalPowered Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.daemon-search.com/startpage
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2031308&q=
.
- - - - ORPHANS REMOVED - - - -
BHO-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\DealioToolbarIE.dll
Toolbar-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\DealioToolbarIE.dll
Toolbar-Locked - (no file)
WebBrowser-{E738F11F-B0F3-4E0D-A5CA-6ED7B0BD4F5D} - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
WebBrowser-{472734EA-242A-422B-ADF8-83D1E48CC825} - (no file)
HKCU-Run-NtSysTools - c:\documents and settings\Windows XP\Desktop\Youtube.exe
HKCU-Run-DLD.EXE - (no file)
HKLM-Run-CTStartup - c:\program files\Creative\Splash Screen\CTEaxSpl.EXE
HKLM-Run-SearchSettings - c:\program files\Dealio Toolbar\SearchSettings.exe
Notify-rqRLefEV - (no file)
AddRemove-Final Fantasy VII XP Patch - c:\program files\Square Soft
AddRemove-Sonic R - c:\sega\SonicR\directx\setup
AddRemove-SONICADVDX - c:\documents and settings\Windows XP\Desktop\Sonic Adventure DX\unsetup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-24 22:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTStartup = c:\program files\Creative\Splash Screen\CTEaxSpl.EXE /run???h??????s?????\?w? ?w???????w???w4???????.??w4???????4???TA?s4???P????&3?????\??? ??? ???\???\???????????5?B~e?B~\???\?????????`??????C@?\???\??????sP???\??????s\????&3?A??s?&3??C@?x???`|?w\?????@
LXCYCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1993962763-879983540-1606980848-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:c5,34,dc,00,c7,52,3e,07,60,ed,d0,f6,b0,08,cd,9f,4f,3f,02,d3,27,2c,83,
89,32,af,02,fa,ee,95,b7,dc,4e,29,f2,3d,82,73,3e,da,3f,56,29,c6,d6,a8,67,0c,\
"??"=hex:5a,87,43,36,1b,a4,0d,b1,5c,07,ac,c0,ad,d7,37,6a
[HKEY_USERS\S-1-5-21-1993962763-879983540-1606980848-1003\Software\SecuROM\License information*]
"datasecu"=hex:a3,74,43,13,72,4b,a5,72,8f,8b,d4,2b,a7,17,b1,c3,a1,c1,cd,68,da,
bf,6d,cf,fa,8b,0d,85,15,4d,bc,c7,c9,bf,e4,81,16,7c,0e,e8,d3,66,1a,fc,64,2b,\
"rkeysecu"=hex:9f,ca,16,75,83,0a,d6,fd,d2,a5,ab,cb,c1,0d,12,f7
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(692)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(748)
c:\windows\system32\xfire_lsp_10650.dll
- - - - - - - > 'explorer.exe'(552)
c:\windows\system32\WININET.dll
c:\windows\system32\ctagent.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lxcycoms.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\AVG\AVG9\avgam.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\MsPMSPSv.exe
c:\kahdah\CF27124.exe
c:\windows\system32\devldr32.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\MsiExec.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\kahdah\PEV.cfxxe
.
**************************************************************************
.
Completion time: 2009-10-25 22:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-25 05:59
Pre-Run: 94,878,535,680 bytes free
Post-Run: 102,184,284,160 bytes free
- - End Of File - - 320C7E206857A5C18A940DCCD5B03699