ComboFix 09-05-18.02 - Windows User 18/05/2009 22:24.4 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.2047.1568 [GMT 1:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Windows User\Application Data\inst.exe c:\windows\system32\drivers\gxvxcrqpxoqoehrlotfaknbriqqjxjdulkwmn.sys c:\windows\system32\gxvxccounter c:\windows\system32\gxvxcltnftlibtbopwcapbabwblddwuynguji.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_GXVXCSERV.SYS ((((((((((((((((((((((((( Files Created from 2009-04-18 to 2009-05-18 ))))))))))))))))))))))))))))))) . 2009-05-18 01:17 . 2009-05-18 17:34 -------- d-----w C:\Poker 2009-05-17 11:48 . 2009-04-06 14:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-05-17 11:48 . 2009-04-06 14:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-05-17 11:48 . 2009-05-18 17:39 -------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-05-17 11:36 . 2009-05-17 11:36 -------- d-----w c:\program files\AskBarDis 2009-05-16 20:13 . 2009-05-16 20:13 -------- d-----w C:\Temp 2009-05-04 15:52 . 2009-05-04 15:52 -------- d-----w c:\documents and settings\Windows User\Local Settings\Application Data\www.pro-evo.xooit.fr 2009-04-30 21:13 . 2009-03-31 17:50 -------- d-----w c:\program files\Microsoft Silverlight 2009-04-30 21:13 . 2009-04-30 21:13 -------- d-----w c:\program files\Microsoft Office Outlook Connector 2009-04-28 11:59 . 2009-04-28 11:59 -------- d-sh--w c:\windows\system32\config\systemprofile\IETldCache 2009-04-28 11:49 . 2009-04-28 11:49 -------- d-sh--w c:\documents and settings\Windows User\IECompatCache 2009-04-27 23:37 . 2009-04-27 23:37 -------- d-----w c:\documents and settings\Windows User\Application Data\uniblue 2009-04-27 23:34 . 2009-04-27 23:34 -------- d-----w c:\program files\Uniblue 2009-04-27 23:29 . 2009-04-27 23:29 -------- d-----w c:\windows\system32\XPSViewer 2009-04-27 23:28 . 2009-04-27 23:28 -------- d-----w c:\program files\Reference Assemblies 2009-04-27 23:27 . 2008-07-06 12:06 117760 ------w c:\windows\system32\prntvpt.dll 2009-04-27 23:27 . 2008-07-06 12:06 89088 ------w c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-04-27 23:27 . 2008-07-06 10:50 597504 ------w c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-04-27 23:27 . 2008-07-06 12:06 575488 ------w c:\windows\system32\dllcache\xpsshhdr.dll 2009-04-27 23:27 . 2008-07-06 12:06 575488 ------w c:\windows\system32\xpsshhdr.dll 2009-04-27 23:27 . 2008-07-06 12:06 1676288 ------w c:\windows\system32\dllcache\xpssvcs.dll 2009-04-27 23:27 . 2008-07-06 12:06 1676288 ------w c:\windows\system32\xpssvcs.dll 2009-04-27 23:27 . 2009-04-27 23:28 -------- d-----w C:\851dc5fc81843ad9db6738b7471f 2009-04-27 23:27 . 2009-04-27 23:32 -------- d-----w c:\windows\SxsCaPendDel 2009-04-27 23:20 . 2009-04-27 23:20 -------- d--h--r C:\AHCache 2009-04-27 15:05 . 2009-04-27 15:05 -------- d-sh--w c:\documents and settings\LocalService\IETldCache . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-17 19:17 . 2008-12-29 19:59 -------- d-----w c:\program files\SUPERAntiSpyware 2009-05-17 12:49 . 2007-12-28 13:15 -------- d-----w c:\program files\Windows Live Safety Center 2009-05-16 20:08 . 2008-11-15 12:46 -------- d-----w c:\program files\mkv2vob 2009-05-04 11:10 . 2009-01-04 11:10 -------- d-----w c:\program files\TVersity Codec Pack 2009-05-03 18:05 . 2009-01-22 22:11 15688 ----a-w c:\windows\system32\lsdelete.exe 2009-05-03 18:04 . 2009-01-22 20:35 64160 ----a-w c:\windows\system32\drivers\Lbd.sys 2009-04-29 13:05 . 2007-12-28 13:53 -------- d-----w c:\program files\Spybot - Search & Destroy 2009-04-28 11:51 . 2009-03-22 12:31 -------- d-----w c:\program files\FLAC 2009-04-27 23:33 . 2007-07-18 09:10 109480 ----a-w c:\documents and settings\Windows User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-04-17 00:13 . 2007-05-21 09:21 -------- d-----w c:\program files\Java 2009-04-12 10:49 . 2009-04-12 10:30 47360 ----a-w c:\documents and settings\Windows User\Application Data\pcouffin.sys 2009-04-12 10:30 . 2009-04-12 10:30 47360 ----a-w c:\windows\system32\drivers\pcouffin.sys 2009-03-20 20:45 . 2009-03-20 20:43 -------- d-----w c:\program files\Microsoft 2009-03-20 20:44 . 2008-12-20 18:58 -------- d-----w c:\program files\Windows Live 2009-03-20 20:43 . 2009-03-20 20:43 -------- d-----w c:\program files\Windows Live SkyDrive 2009-03-19 22:41 . 2007-07-28 21:14 -------- d-----w c:\program files\Google 2009-03-09 04:19 . 2008-12-29 19:56 410984 ----a-w c:\windows\system32\deploytk.dll 2009-03-08 04:34 . 2004-08-10 15:38 914944 ----a-w c:\windows\system32\wininet.dll 2009-03-08 04:34 . 2004-08-10 15:37 43008 ----a-w c:\windows\system32\licmgr10.dll 2009-03-08 04:33 . 2004-08-10 15:37 18944 ----a-w c:\windows\system32\corpol.dll 2009-03-08 04:33 . 2004-08-10 15:38 420352 ----a-w c:\windows\system32\vbscript.dll 2009-03-08 04:32 . 2004-08-10 15:37 72704 ----a-w c:\windows\system32\admparse.dll 2009-03-08 04:32 . 2004-08-10 15:37 71680 ----a-w c:\windows\system32\iesetup.dll 2009-03-08 04:31 . 2004-08-10 15:37 34816 ----a-w c:\windows\system32\imgutil.dll 2009-03-08 04:31 . 2004-08-10 15:38 48128 ----a-w c:\windows\system32\mshtmler.dll 2009-03-08 04:31 . 2004-08-10 15:38 45568 ----a-w c:\windows\system32\mshta.exe 2009-03-08 04:22 . 2004-08-10 15:38 156160 ----a-w c:\windows\system32\msls31.dll 2009-03-06 14:22 . 2004-08-10 15:38 284160 ----a-w c:\windows\system32\pdh.dll 2009-02-23 10:11 . 2009-02-24 19:09 130424 ----a-w c:\windows\system32\drivers\PCTCore.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}] 2008-08-06 14:20 279944 ----a-w c:\program files\AskBarDis\bar\bin\askBar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SmpcSys"="c:\apps\SMP\SmpSys.exe" [2005-11-17 975360] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "EPSON Stylus DX8400 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATICEE.EXE" [2007-04-12 182272] "TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2008-12-09 234856] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-28 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952] "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168] "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168] "SMSERIAL"="c:\windows\sm56hlpr.exe" [2006-03-21 544768] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-16 794713] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-08 7573504] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-05-08 86016] "DetectorApp"="c:\program files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe" [2005-10-20 102400] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-08-09 221184] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-08-09 81920] "HControl"="c:\windows\ATK0100\HControl.exe" [2006-02-23 106496] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352] "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-05-03 516440] "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888] "High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-05-08 1519616] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 11:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk backup=c:\windows\pss\Google Updater.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Windows User^Start Menu^Programs^Startup^Microsoft Office Groove.lnk] path=c:\documents and settings\Windows User\Start Menu\Programs\Startup\Microsoft Office Groove.lnk backup=c:\windows\pss\Microsoft Office Groove.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "WLSetupSvc"=3 (0x3) "usnjsvc"=3 (0x3) "UleadBurningHelper"=2 (0x2) "ose"=3 (0x3) "Nero BackItUp Scheduler 3"=2 (0x2) "LiveUpdate Notice Service"=2 (0x2) "LiveUpdate Notice Ex"=2 (0x2) "LiveUpdate"=3 (0x3) "iPod Service"=3 (0x3) "avg8wd"=2 (0x2) "Automatic LiveUpdate Scheduler"=2 (0x2) "Adobe LM Service"=3 (0x3) "aawservice"=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%ProgramFiles%\\AOL 9.0\\aol.exe"= "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"= "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\InterActual\\BitTorrent\\bittorrent.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\BitTorrent\\bittorrent.exe"= "c:\\apps\\skype\\Phone\\Skype.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcstart.exe"= "c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"= R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [22/01/2009 21:35 64160] R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [24/02/2009 20:09 130424] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [22/12/2008 12:06 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [22/12/2008 12:05 55024] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18/01/2009 22:34 953168] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [22/12/2008 12:06 7408] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12 . Contents of the 'Scheduled Tasks' folder 2009-05-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 18:04] 2009-05-16 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 11:34] 2009-05-18 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-07-28 17:35] . . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uStart Page = hxxp://www.google.co.uk/ Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxp://www.facebook.com/controls/contactx.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-05-18 22:28 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h��|�������|��A~*] "AB141C35E9F4BF344B9FC010BB17F68A"="" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(616) c:\program files\SUPERAntiSpyware\SASWINLO.dll . Completion time: 2009-05-18 22:30 ComboFix-quarantined-files.txt 2009-05-18 21:30 Pre-Run: 26,381,324,288 bytes free Post-Run: 26,377,695,232 bytes free 226 --- E O F --- 2009-05-13 07:46