ComboFix 08-10-15.05 - Administrator 10/16/2008 3:32:31.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.820 [GMT 3:00]
Running from: D:\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\al-amiaz\My Documents\My Documents.url
C:\Documents and Settings\al-amiaz\My Documents\My Music\My Music.url
C:\Documents and Settings\al-amiaz\My Documents\My Pictures\My Pictures.url
C:\Documents and Settings\al-amiaz\My Documents\My Videos\My Video.url
C:\WINDOWS\system32\Desktop_.ini
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\wav.cpl
.
((((((((((((((((((((((((( Files Created from 2008-09-16 to 2008-10-16 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-16 00:37 --------- d-----w C:\Documents and Settings\al-amiaz\Application Data\Orbit
2008-10-16 00:01 3,070 ----a-w C:\WINDOWS\system32\tmp.reg
2008-10-15 22:57 35,363 ----a-w C:\WINDOWS\system32\windrvNT.sys
2008-10-15 22:31 --------- d-----w C:\Documents and Settings\al-amiaz\Application Data\Comodo
2008-10-15 22:30 --------- d-----w C:\Documents and Settings\al-amiaz\Application Data\Avant Profiles
2008-10-15 22:24 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-15 22:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\comodo
2008-10-15 22:23 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Orbit
2008-10-15 22:06 249,592 ----a-w C:\WINDOWS\system32\cssdll32.dll
2008-10-15 22:06 --------- d-----w C:\Program Files\COMODO
2008-10-15 22:06 --------- d-----w C:\Program Files\AskSearch
2008-10-15 22:05 99,600 ----a-w C:\WINDOWS\system32\drivers\cmdguard.sys
2008-10-15 22:05 24,080 ----a-w C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-10-15 22:05 143,104 ----a-w C:\WINDOWS\system32\guard32.dll
2008-10-15 21:45 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Avant Profiles
2008-10-15 21:44 --------- d-----w C:\Program Files\Avant Browser
2008-10-15 21:04 --------- d-----w C:\Program Files\Orbitdownloader
2008-10-15 20:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-15 19:55 --------- d-----w C:\Program Files\MSXML 4.0
2008-10-15 19:48 --------- d-----w C:\Program Files\WAV
2008-10-12 17:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2008-10-12 17:33 --------- d-----w C:\Program Files\Nokia
2008-10-12 17:32 --------- d-----w C:\Program Files\MSXML 6.0
2008-10-12 17:32 --------- d-----w C:\Program Files\Common Files\Nokia
2008-10-12 17:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-10-08 00:13 90,112 ----a-w C:\WINDOWS\system32\agsaami.dll
2008-10-08 00:13 610,304 ----a-w C:\WINDOWS\system32\agsaamg.dll
2008-10-08 00:13 372,736 ----a-w C:\WINDOWS\system32\agsaamc.dll
2008-10-08 00:13 2,535,424 ----a-w C:\WINDOWS\system32\agsaamj.dll
2008-10-08 00:13 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-10-08 00:13 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-10-08 00:13 1,245,184 ----a-w C:\WINDOWS\system32\bkll.dll
2008-10-08 00:13 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-10-08 00:13 --------- d-----w C:\Program Files\Real_SC
2008-09-17 14:52 53,248 ----a-w C:\WINDOWS\system32\suppdll.dll
2008-09-17 14:52 --------- d-----w C:\Program Files\Folder Lock
2008-09-17 14:36 --------- d-----w C:\Documents and Settings\al-amiaz\Application Data\DivX
2008-09-15 15:37 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-13 15:09 --------- d-----w C:\Documents and Settings\al-amiaz\Application Data\Nokia
2008-09-06 14:30 --------- d-----w C:\Documents and Settings\al-amiaz\Application Data\GrabPro
2008-09-06 11:43 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-09-06 11:43 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-09-06 11:43 --------- d-----w C:\Documents and Settings\al-amiaz\Application Data\PC Suite
2008-09-06 11:31 --------- d-----w C:\Documents and Settings\al-amiaz\Application Data\vlc
2008-09-06 11:28 --------- d-----w C:\Documents and Settings\al-amiaz\Application Data\Nokia Multimedia Player
2008-09-06 11:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-09-06 11:24 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-09-06 11:24 --------- d-----w C:\Program Files\DIFX
2008-09-06 11:24 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-09-06 11:20 --------- d-----w C:\Documents and Settings\al-amiaz\Application Data\ESET
2008-09-06 11:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-09-06 11:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-06 11:11 --------- d-----w C:\Program Files\Microsoft Works
2008-09-06 11:10 --------- d-----w C:\Program Files\MSBuild
2008-09-06 11:05 --------- d-----w C:\Program Files\DivX
2008-09-06 11:04 --------- d-----w C:\Program Files\VideoLAN
2008-09-06 11:04 --------- d-----w C:\Program Files\Fantasysoft-Studio
2008-09-06 11:03 --------- d-----w C:\Program Files\Yahoo!
2008-09-06 11:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-09-06 11:02 --------- d-----w C:\Program Files\Windows Live
2008-09-06 11:02 --------- d-----w C:\Program Files\Java
2008-09-06 11:02 --------- d-----w C:\Program Files\Common Files\Java
2008-09-06 10:58 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-09-06 10:58 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-09-06 10:58 --------- d-----w C:\Program Files\Real
2008-09-06 10:58 --------- d-----w C:\Program Files\Common Files\xing shared
2008-09-06 10:58 --------- d-----w C:\Program Files\Common Files\Real
2008-09-06 10:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-09-06 10:57 --------- d-----w C:\Program Files\Nero
2008-09-06 10:57 --------- d-----w C:\Program Files\Common Files\Nero
2008-09-06 10:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-09-06 10:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-06 10:56 --------- d-----w C:\Program Files\CyberLink
2008-09-06 10:48 --------- d-----w C:\Program Files\JetAudio
2008-09-06 10:48 --------- d-----w C:\Program Files\Common Files\COWON
2008-09-06 10:42 --------- d-----w C:\Program Files\Marvell
2008-09-06 10:42 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-06 10:29 --------- d-----w C:\Program Files\WIDCOMM
2008-09-06 10:24 --------- d-----w C:\Program Files\Broadcom
2008-09-06 10:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\QMI
2008-09-06 10:20 --------- d-----w C:\Program Files\Atheros
2008-09-06 10:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Atheros
2008-09-06 10:20 --------- d-----w C:\Documents and Settings\al-amiaz\Application Data\InstallShield
2008-09-06 10:16 --------- d-----w C:\Program Files\Synaptics
2008-09-06 10:13 --------- d-----w C:\Program Files\Realtek
2008-09-06 10:06 --------- d-----w C:\Program Files\Intel
2008-09-06 10:00 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-20 05:36 657,920 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:42 2,137,600 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:42 2,017,280 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [08/16/2007 04:19 PM 5728112]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [10/27/2007 07:51 AM 3810544]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [03/26/2008 06:41 PM 1232896]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [04/16/2008 12:53 PM 1079808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [06/13/2006 04:57 AM 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [06/13/2006 04:57 AM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [06/13/2006 04:57 AM 118784]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [07/19/2006 04:41 AM 53248]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [04/29/2006 06:13 AM 766041]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [03/14/2007 09:01 PM 71216]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [03/14/2007 09:01 PM 54832]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/06/2008 01:58 PM 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [09/06/2008 02:02 PM 77824]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM 31016]
"COMODO SafeSurf"="C:\Program Files\COMODO\SafeSurf\cssurf.exe" [10/16/2008 01:06 AM 278264]
"COMODO Internet Security"="C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" [10/16/2008 01:05 AM 1845504]
"RTHDCPL"="RTHDCPL.EXE" [07/19/2006 04:42 AM 16248320 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [07/19/2006 04:42 AM 2879488 C:\WINDOWS\SkyTel.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 12:56 AM 110592 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
C:\Documents and Settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-01-17 618557]
Orbit.lnk - C:\Program Files\Orbitdownloader\orbitdm.exe [2008-09-06 1707208]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-09-06 389120]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [10/16/2008 01:05 AM 99600]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [10/16/2008 01:05 AM 24080]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\
000.fcl [09/19/2007 09:37 PM 41456]
S3 btwaudio;Bluetooth Audio Device Service;C:\WINDOWS\system32\drivers\btwaudio.sys [11/06/2006 12:37 PM 78128]
S3 btwavdt;Bluetooth AVDT;C:\WINDOWS\system32\drivers\btwavdt.sys [11/06/2006 10:13 AM 80176]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [02/01/2008 04:17 PM 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [02/01/2008 04:17 PM 8320]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-wblogon - C:\WINDOWS\system32\algg.exe
HKCU-Run-VirRL2009 - C:\Program Files\VirRL2009\VirRL2009.exe
HKLM-Run-BroadcomWireless - C:\Program Files\Broadcom\Wireless\Utility\WlanUtil.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://windiwsfsearch.com/search?q={searchTerms}
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
O8 -: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 -: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 -: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 -: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 -: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 -: ت&صدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-16 03:37:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\sccfg.sys 20 bytes
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\
000.fcl"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\DOCUME~1\al-amiaz\LOCALS~1\temp\RtkBtMnt.exe
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 10/16/2008 3:39:26 - machine was rebooted [al-amiaz]
ComboFix-quarantined-files.txt 2008-10-16 00:39:10
Pre-Run: 24,545,845,248 bytes free
Post-Run: 24,483,209,216 bytes free
218 --- E O F --- 2008-10-16 00:16:43