ComboFix 09-04-15.08 - Winxp 04/16/2009 7:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.223.67 [GMT 3:00]
Running from: c:\documents and settings\Winxp\My Documents\Downloads\Programs\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
c:\windows\system32\drivers\npf.sys
c:\windows\system32\info.txt
c:\windows\system32\Packet.dll
c:\windows\system32\pfxzmtsmtspm.dll
c:\windows\system32\sfxzmtsmtspm.dll
c:\windows\system32\sfxzmtwbmail.dll
c:\windows\system32\tmp.reg
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MSUPDATE
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-03-16 to 2009-04-16 )))))))))))))))))))))))))))))))
.
2009-04-16 03:16 . 2009-04-16 03:16 -------- dc----w c:\documents and settings\Winxp\Application Data\CyberScrub
2009-04-16 03:15 . 2009-04-16 03:16 -------- dc----w c:\documents and settings\Winxp\Application Data\cleaner
2009-03-27 04:15 . 2009-03-27 04:15 4 -c--a-w c:\windows\RegDefrag.dat
2009-03-27 04:04 . 2009-03-27 06:08 -------- dc----w c:\program files\Registry Compressor
2009-03-27 03:50 . 2009-03-27 03:50 42 ----a-w c:\windows\system32\RegistryFast.lie
2009-03-27 03:50 . 2009-03-27 06:02 -------- dc----w c:\program files\Registry Fast
2009-03-27 03:16 . 2009-03-27 06:07 41144 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-27 03:16 . 2009-03-27 06:07 3330080 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-25 05:53 . 2009-01-29 22:00 36352 -c----w C:\WGASetup.exe
2009-03-25 05:53 . 2009-01-29 22:00 190464 -c----w C:\WgaLogon.dll
2009-03-25 05:52 . 2009-01-29 22:00 323072 -c----w C:\WgaTray.exe
2009-03-25 05:52 . 2009-01-29 22:00 1481728 -c--a-w C:\LegitCheckControl.dll
2009-03-25 03:09 . 2009-02-13 08:31 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-03-25 03:09 . 2009-03-25 03:09 -------- dc----w c:\program files\Avira
2009-03-25 03:09 . 2009-03-25 03:09 -------- dc----w c:\documents and settings\All Users\Application Data\Avira
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-16 04:09 . 2007-07-17 08:17 -------- dc----w c:\documents and settings\Winxp\Application Data\DMCache
2009-04-14 00:37 . 2007-02-08 23:18 288857 -c--a-w C:\winzip.log
2009-04-01 13:58 . 2007-07-17 08:17 -------- dc----w c:\documents and settings\Winxp\Application Data\IDM
2009-03-27 06:56 . 2009-03-27 06:38 2471 -c--a-w C:\rapport.txt
2009-03-27 02:57 . 2007-07-17 08:17 -------- dc----w c:\program files\Internet Download Manager
2009-03-25 08:50 . 2007-12-13 20:21 -------- dc----w c:\program files\themexp
2009-03-25 08:49 . 2006-12-05 04:07 -------- dc----w c:\program files\Real_SC
2009-03-25 08:34 . 2009-01-21 01:08 -------- dc----w c:\program files\LtUcx
2009-03-25 08:27 . 2008-12-18 22:57 -------- dc----w c:\program files\Circle Developement
2009-03-25 01:51 . 2006-12-05 04:55 150 -c--a-w C:\YServer.txt
2009-03-25 01:48 . 2006-12-05 04:09 -------- dc-h--w c:\program files\InstallShield Installation Information
2009-03-11 17:42 . 2006-12-05 04:38 -------- dc----w c:\program files\Microsoft SDK for Java 4.0
2009-03-11 17:28 . 2006-12-05 03:52 -------- dc----w c:\program files\Golden Al-Wafi Translator
2009-03-08 09:04 . 2007-06-06 09:39 -------- dc----w c:\program files\Windows Live
2009-03-08 09:02 . 2008-01-13 18:26 -------- dc----w c:\documents and settings\All Users\Application Data\WLInstaller
2009-03-06 05:20 . 2008-04-05 21:20 -------- dc----w c:\program files\Common Files\LogoManager
2009-03-06 05:20 . 2008-04-05 21:20 -------- dc----w c:\program files\MobiMB Mobile Media Browser
2009-02-26 09:04 . 2009-02-26 09:04 -------- dc----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-02-19 23:36 . 2009-02-19 23:32 -------- dc----w c:\documents and settings\All Users\Application Data\Bluetooth
2009-02-19 22:49 . 2009-02-19 22:49 -------- dc----w c:\program files\IVT Corporation
2009-02-09 11:13 . 2004-08-03 20:17 1846784 ----a-w c:\windows\system32\win32k.sys
2009-01-22 14:49 . 2009-01-22 14:39 206256 ----a-w c:\windows\system32\idmmbc.dll
2009-01-11 04:23 . 2006-12-05 03:07 164200 -c--a-w c:\documents and settings\Winxp\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-03-27 2745776]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2009-2-20 1183744]
SnagIt 8.lnk - c:\program files\TechSmith\SnagIt 8\SnagIt32.exe [2007-2-16 6379080]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.DIV3"= DIVXc32.dll
"vidc.DIV4"= DIVXc32f.dll
"msacm.divxa32"= DivXa32.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SnagIt 7.lnk]
backup=c:\windows\pss\SnagIt 7.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Watch.lnk]
backup=c:\windows\pss\Watch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Winxp^Start Menu^Programs^Startup^Webshots.lnk]
backup=c:\windows\pss\Webshots.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\AppServ\\apache\\Apache.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:UDP"= 443:UDP

oVoo UDP port 443
"37674:TCP"= 37674:TCP

oVoo TCP port 37674
"37674:UDP"= 37674:UDP

oVoo UDP port 37674
"37675:UDP"= 37675:UDP

oVoo UDP port 37675
"443:TCP"= 443:TCP

oVoo TCP port 443
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-05 108289]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [2007-01-11 194304]
--- Other Services/Drivers In Memory ---
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - RasMan
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - SeaPort
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - TapiSrv
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - W32Time
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
MSConfigStartUp-ooVoo - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-16 07:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1202660629-113007714-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*t*t* \OpenWithList]
@Class="Shell"
"a"="MsnMsgr.Exe"
"MRUList"="a"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{44af2821-fcb9-426a-9f97-3a83a86e916b}]
@Denied: (Full) (Everyone)
"Model"=dword:00000166
"Therad"=dword:0000001b
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):5f,64,69,76,ca,d2,aa,c6,6b,d8,c8,28,65,ab,fc,4b,2f,e8,e5,89,45,
09,45,e4,f1,f8,e4,ea,eb,a2,2e,76,3e,91,33,78,1e,b7,a2,aa,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):77,05,67,e6,1b,55,d3,0a,78,cf,a3,16,42,0d,d2,d6,72,7e,f1,42,f1,
e3,f6,35,8a,66,8a,32,3e,4e,42,cf,33,0f,dc,fc,a0,d1,24,bc,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{982c672c-9a96-4f04-aab7-3803feb25c1d}]
@Denied: (Full) (Everyone)
"Model"=dword:000000e2
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\appserv\apache\Apache.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\windows\system32\Crypserv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\appserv\MySQL\bin\mysqld-nt.exe
c:\appserv\apache\Apache.exe
c:\program files\TechSmith\SnagIt 8\TscHelp.exe
c:\program files\TechSmith\SnagIt 8\SnagPriv.exe
c:\program files\Internet Explorer\iexplore.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-16 7:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-16 04:21
Pre-Run: 9,702,981,632 bytes free
Post-Run: 9,639,636,992 bytes free
226 --- E O F --- 2009-03-14 21:03