COMBOFIX LOG:
ComboFix 10-01-29.05 - Jeffro 01/29/2010 22:28:33.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.958.517 [GMT -5:00]
Running from: c:\documents and settings\Jeffro\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-30 )))))))))))))))))))))))))))))))
.
2010-01-27 05:27 . 2010-01-18 16:42 1260800 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-27 05:27 . 2010-01-18 16:41 3777280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-25 01:44 . 2010-01-25 01:44 -------- d-----w- C:\rsit
2010-01-25 00:29 . 2010-01-25 00:29 -------- d-----w- c:\documents and settings\Wifey\Application Data\Malwarebytes
2010-01-25 00:29 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-25 00:29 . 2010-01-25 00:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-25 00:29 . 2010-01-25 00:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-25 00:29 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-22 00:01 . 2010-01-22 00:01 -------- d-----w- c:\documents and settings\Jeffro\Application Data\MSNInstaller
2010-01-19 03:13 . 2010-01-19 03:13 -------- d-----w- c:\program files\Trend Micro
2010-01-18 16:36 . 2010-01-21 03:59 -------- d-----w- c:\documents and settings\Jeffro\Local Settings\Application Data\nsydma
2010-01-08 03:52 . 2010-01-08 03:52 -------- d-----w- c:\program files\Common Files\Research In Motion
2010-01-08 03:52 . 2010-01-08 03:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Research In Motion
2010-01-03 06:50 . 2010-01-29 02:55 -------- d-----w- c:\documents and settings\All Users\Lx_cats
2010-01-03 06:49 . 2010-01-03 06:49 -------- d-----w- C:\logs
2010-01-03 06:49 . 2008-02-28 00:15 40960 ----a-w- c:\windows\system32\lxdxvs.dll
2010-01-03 06:49 . 2008-02-19 04:14 360448 ----a-w- c:\windows\system32\lxdxcoin.dll
2010-01-03 06:49 . 2008-02-28 00:15 115200 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\lxdxdrpp.dll
2010-01-03 06:48 . 2001-08-18 03:36 87040 -c--a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2010-01-03 06:48 . 2001-08-18 03:36 87040 ----a-w- c:\windows\system32\wiafbdrv.dll
2010-01-03 06:48 . 2008-02-28 00:11 81920 ----a-w- c:\windows\system32\lxdxcaps.dll
2010-01-03 06:48 . 2008-02-28 00:11 782336 ----a-w- c:\windows\system32\lxdxdrs.dll
2010-01-03 06:48 . 2008-02-28 00:02 69632 ----a-w- c:\windows\system32\lxdxcnv4.dll
2010-01-03 06:47 . 2010-01-03 06:47 -------- d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
2010-01-03 06:45 . 2007-07-26 16:23 1645320 ----a-w- c:\windows\system32\gdiplus.dll
2010-01-03 06:45 . 2010-01-03 06:45 -------- d-----w- c:\program files\Lexmark Toolbar
2010-01-03 06:43 . 2010-01-03 06:55 -------- d-----w- c:\program files\Lexmark 3600-4600 Series
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-31 22:44 . 2009-12-22 23:47 3966744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-12-21 19:14 . 2004-08-04 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-12-11 01:29 . 2009-12-11 01:29 42304 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-11 01:29 . 2009-12-11 01:29 -------- d-----w- c:\documents and settings\Guest\Application Data\HP
2009-12-09 04:44 . 2009-12-09 04:44 -------- d-----w- c:\documents and settings\Guest\Application Data\Apple Computer
2009-12-08 05:23 . 2009-12-08 05:22 -------- d--h--r- c:\documents and settings\Guest\Application Data\yahoo!
2009-12-08 05:22 . 2009-12-08 05:22 -------- d-----w- c:\documents and settings\Guest\Application Data\HotSync
2009-12-01 05:20 . 2009-11-03 11:54 276088 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-11-22 00:15 . 2009-11-22 00:15 1961720 ----a-w- c:\documents and settings\Jeffro\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-11-21 23:18 . 2009-11-21 23:18 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-21 23:18 . 2009-11-21 23:18 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-21 23:18 . 2009-11-21 23:18 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-21 23:18 . 2009-11-21 23:18 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-21 16:36 . 2004-08-04 12:00 470528 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-03 00:53 . 2008-08-13 23:10 42304 -c--a-w- c:\documents and settings\Wifey\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-02 05:09 . 2007-11-12 03:40 42304 -c--a-w- c:\documents and settings\Jeffro\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
1998-12-09 02:53 . 1998-12-09 02:53 99840 -c--a-w- c:\program files\Common Files\IRAABOUT.DLL
1998-12-09 02:53 . 1998-12-09 02:53 70144 -c--a-w- c:\program files\Common Files\IRAMDMTR.DLL
1998-12-09 02:53 . 1998-12-09 02:53 48640 -c--a-w- c:\program files\Common Files\IRALPTTR.DLL
1998-12-09 02:53 . 1998-12-09 02:53 31744 -c--a-w- c:\program files\Common Files\IRAWEBTR.DLL
1998-12-09 02:53 . 1998-12-09 02:53 186368 -c--a-w- c:\program files\Common Files\IRAREG.DLL
1998-12-09 02:53 . 1998-12-09 02:53 17920 -c--a-w- c:\program files\Common Files\IRASRIAL.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 65536]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"QuickTime Task"="x:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2008-11-25 356352]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-12-31 2033432]
"lxdxmon.exe"="c:\program files\Lexmark 3600-4600 Series\lxdxmon.exe" [2008-06-13 668328]
"lxdxamon"="c:\program files\Lexmark 3600-4600 Series\lxdxamon.exe" [2008-06-13 16040]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HOTSYNCSHORTCUTNAME.lnk - c:\program files\palmOne\Hotsync.exe [2004-6-9 471040]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-21 23:18 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\WINDOWS\\system32\\lxdxcoms.exe"=
"c:\\Program Files\\Lexmark 3600-4600 Series\\lxdxamon.exe"=
"c:\\Program Files\\Lexmark 3600-4600 Series\\frun.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
"c:\\Program Files\\Lexmark 3600-4600 Series\\lxdxmon.exe"=
"c:\\WINDOWS\\system32\\lxdxcfg.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdxpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdxtime.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdxjswx.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/21/2009 6:18 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/21/2009 6:18 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/21/2009 6:18 PM 285392]
R2 lxdx_device;lxdx_device;c:\windows\system32\lxdxcoms.exe -service --> c:\windows\system32\lxdxcoms.exe -service [?]
S2 lxdxCATSCustConnectService;lxdxCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdxserv.exe [1/3/2010 1:49 AM 98984]
.
Contents of the 'Scheduled Tasks' folder
2009-01-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.yahoo.com/uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) =
hxxp://us.rd.yahoo.com/customize/ycomp/ ... .yahoo.com.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-29 22:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3264)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-01-29 22:35:04
ComboFix-quarantined-files.txt 2010-01-30 03:34
ComboFix2.txt 2010-01-29 12:58
ComboFix3.txt 2010-01-28 02:40
Pre-Run: 11,651,108,864 bytes free
Post-Run: 12,054,192,128 bytes free
- - End Of File - - 3B1D72BAED1E5A6A7DEFE2B17143E5C5