ComboFix Log
ComboFix 09-12-29.04 - KoOl DoG 12/29/2009 23:46:04.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.958.460 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\KoOl DoG\Desktop\CFScript.txt
* Resident AV is active
file zipped: C:\dqhwx.exe
file zipped: C:\kobyh.exe
file zipped: C:\osajmkfd.exe
file zipped: C:\qllp.exe
file zipped: c:\windows\system32\drivers\cxtpw.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\ANYONE\3JMV42N7
c:\documents and settings\ANYONE\3JMV42N7\oXMLBranch[1].xml
c:\documents and settings\CINDY~1\3JMV42N7
c:\documents and settings\CINDY~1\5UXXRDNS
c:\documents and settings\CINDY~1\69ITISPZ
c:\documents and settings\CINDY~1\72J13IBS
c:\documents and settings\CINDY~1\72J13IBS\oXMLBranch[1].xml
c:\documents and settings\CINDY~1\97RH9W9R
c:\documents and settings\CINDY~1\9AVE884D
c:\documents and settings\CINDY~1\9AVE884D\oXMLBranch[1].xml
c:\documents and settings\CINDY~1\M4XSWRZ3
c:\documents and settings\CINDY~1\Z52HJ6WF
c:\documents and settings\KoOl DoG\8XAM1ND8
c:\documents and settings\KoOl DoG\IQZUCG6S
c:\documents and settings\KoOl DoG\KSFHMK74
c:\documents and settings\KoOl DoG\OJHZINK5
C:\dqhwx.exe
C:\kobyh.exe
C:\osajmkfd.exe
c:\program files\InternetSecurity2010
C:\qllp.exe
c:\windows\system32\drivers\cxtpw.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_cxtpw
——-\Service_cxtpw
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-30 )))))))))))))))))))))))))))))))
.
2009-12-24 01:55 . 2009-11-10 15:26 767952 —-a-w- c:\windows\BDTSupport.dll
2009-12-24 01:55 . 2009-11-10 15:28 149456 —-a-w- c:\windows\SGDetectionTool.dll
2009-12-24 01:55 . 2009-11-10 15:28 165840 —-a-w- c:\windows\PCTBDRes.dll
2009-12-24 01:55 . 2009-11-10 15:28 1640400 —-a-w- c:\windows\PCTBDCore.dll
2009-12-24 01:55 . 2009-10-28 06:36 1152444 —-a-w- c:\windows\UDB.zip
2009-12-24 01:55 . 2008-11-26 17:08 131 —-a-w- c:\windows\IDB.zip
2009-12-24 01:53 . 2009-10-30 16:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-12-24 01:53 . 2009-11-09 16:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-12-24 01:53 . 2009-10-06 21:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-12-24 01:53 . 2009-09-03 14:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-12-24 01:53 . 2009-12-29 23:09 ——– d—–w- c:\program files\Spyware Doctor
2009-12-24 01:53 . 2009-12-24 01:56 ——– d—–w- c:\program files\Common Files\PC Tools
2009-12-24 01:53 . 2009-12-24 01:53 ——– d—–w- c:\documents and settings\KoOl DoG\Application Data\PC Tools
2009-12-24 01:53 . 2009-12-24 01:53 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-12-23 23:56 . 2009-12-23 23:56 ——– d—–w- C:\spoolerlogs
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-30 04:55 . 2008-05-20 23:04 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-29 23:39 . 2008-11-23 19:08 ——– d—–w- c:\program files\Spyware Terminator
2009-12-29 15:33 . 2008-11-23 19:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-12-28 05:28 . 2006-12-26 21:32 ——– d—–w- c:\program files\Lx_cats
2009-12-28 04:39 . 2008-11-23 19:11 ——– d—–w- c:\program files\WinClamAVShield
2009-12-25 15:04 . 2008-11-23 19:09 ——– d—–w- c:\documents and settings\KoOl DoG\Application Data\Spyware Terminator
2009-12-25 02:17 . 2008-11-28 04:37 ——– d—–w- c:\documents and settings\ANYONE\Application Data\Spyware Terminator
2009-12-22 19:31 . 2005-09-19 23:12 ——– d—–w- c:\program files\Hewlett-Packard
2009-12-22 19:31 . 2005-09-19 22:50 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-21 20:27 . 2008-11-26 20:53 ——– d—–w- c:\program files\GIMP-2.0
2009-12-19 17:11 . 2009-05-05 20:46 32768 –sha-w- c:\documents and settings\ANYONE\index.dat
2009-12-19 17:11 . 2009-02-18 18:37 32768 –sha-w- c:\documents and settings\CINDY~1\index.dat
2009-12-19 00:36 . 2009-02-16 21:24 32768 –sha-w- c:\documents and settings\KoOl DoG\index.dat
2009-12-17 02:21 . 2008-09-10 20:50 ——– d—–w- c:\program files\OGPlanet
2009-11-26 18:20 . 2007-07-14 23:43 72320 -c–a-w- c:\documents and settings\ANYONE\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-29 07:45 . 2004-08-04 12:00 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 06:00 . 2004-08-04 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 06:00 . 2004-08-04 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:58 . 2004-08-04 12:00 263552 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:53 . 2004-08-04 12:00 266752 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:54 . 2004-08-04 12:00 69632 —-a-w- c:\windows\system32\raschap.dll
2009-10-12 13:54 . 2004-08-04 12:00 112128 —-a-w- c:\windows\system32\rastls.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\spoolerlogs —-
2009-12-23 23:56 . 2009-12-23 23:56 14693 —-a-w- c:\spoolerlogs\spooler.xml
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-17 68856]
"NCLaunch"="c:\windows\NCLAUNCH.EXe" [2007-02-18 40960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"SMSERIAL"="sm56hlpr.exe" [2005-01-24 544768]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-11 253952]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"StormCodec_Helper"="c:\program files\Ringz Studio\Storm Codec\StormSet.exe" [2005-02-07 94037]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-02-27 180269]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2006-10-21 921600]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"LXCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 73728]
"lxcgmon.exe"="c:\program files\Lexmark 2300 Series\lxcgmon.exe" [2005-07-21 200704]
"EzPrint"="c:\program files\Lexmark 2300 Series\ezprint.exe" [2005-08-01 94208]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 299008]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-07 30192]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2007-11-16 2065648]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-11-23 2246144]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-06 177472]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\system32\\lxcgcoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxcgpswx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [12/23/2009 8:53 PM 207792]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [11/23/2008 2:09 PM 142592]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [12/23/2009 8:55 PM 112592]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 5:16 PM 24652]
S3 Radialpoint Security Services;Radialpoint Security Services;c:\windows\system32\dllhost.exe [8/4/2004 7:00 AM 5120]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [12/23/2009 8:53 PM 359624]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
LSP: c:\windows\system32\imon.dll
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-29 23:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCGCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Syncmgr\ProgressState\K*E*V*I*N*A*N*D*C*I*N*D*Y*_*e&C*i*n*d*y*e&\{00000000-0000-0000-0000-000000000000}]
"Expanded"=dword:00000001
"PushPin"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(580)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(636)
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
- - - - - - - > 'explorer.exe'(3464)
c:\windows\system32\WININET.dll
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Authentium\AntiVirus\dvpapi.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Eset\nod32krn.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\sm56hlpr.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\lxcgcoms.exe
c:\windows\system32\MsiExec.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-12-30 00:03:14 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-30 05:03
ComboFix2.txt 2009-12-29 23:46
Pre-Run: 128,569,683,968 bytes free
Post-Run: 130,040,459,264 bytes free
- - End Of File - - 0ADA55BBBA2BB4466511D67E21DA246E
MBAM Log
Malwarebytes' Anti-Malware 1.42
Database version: 3454
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702
12/30/2009 12:15:16 AM
mbam-log-2009-12-30 (00-15-16).txt
Scan type: Quick Scan
Objects scanned: 126499
Time elapsed: 5 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udfa (Backdoor.Bot) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\KoOl DoG\ntload.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\ntload.dll (Trojan.Agent) -> Quarantined and deleted successfully.
I ran the Kaspersky report 2 times and I ended up with white screen, so it didn't work.
Before getting the white screen it said that I had 5 infections.