ComboFix 09-04-22.02 - user 04/21/2009 11:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.502.207 [GMT 3:00]
Running from: c:\downloads\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
c:\windows\msnimport.exe
c:\windows\system32\dllcache\autorun.inf
c:\windows\system32\Ultra.dll
c:\windows\system32\winio.vxd
.
((((((((((((((((((((((((( Files Created from 2009-03-22 to 2009-04-22 )))))))))))))))))))))))))))))))
.
2009-04-21 04:08 . 2009-04-21 08:43 -------- d-----w c:\documents and settings\user\Application Data\MessengerLog 360
2009-04-11 08:19 . 2009-04-11 08:19 70984 ----a-w c:\documents and settings\user\g2mdlhlpx.exe
2009-03-25 21:55 . 2009-03-25 21:55 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-03-25 12:51 . 2009-03-25 12:51 -------- d-----w c:\documents and settings\user\Local Settings\Application Data\Real
2009-03-25 12:48 . 2009-03-25 12:48 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-21 08:42 . 2008-01-24 19:21 -------- d-----w c:\program files\FlashGet
2009-04-20 22:14 . 2001-09-19 12:00 70448 ----a-w c:\windows\system32\perfc001.dat
2009-04-20 22:14 . 2001-09-19 12:00 370894 ----a-w c:\windows\system32\perfh001.dat
2009-04-15 20:09 . 2008-01-24 20:35 -------- d-----w c:\documents and settings\user\Application Data\Skype
2009-04-13 05:51 . 2008-09-03 16:33 -------- d-----w c:\program files\Intelligent Control Screen
2009-04-11 08:20 . 2009-04-11 08:20 -------- d-----w c:\program files\Citrix
2009-03-30 07:56 . 2009-03-09 23:05 -------- d-----w c:\program files\Video Convert Master
2009-03-25 12:50 . 2009-03-25 12:50 -------- d-----w c:\program files\Common Files\xing shared
2009-03-25 12:50 . 2008-01-24 17:16 -------- d-----w c:\program files\Common Files\Real
2009-03-25 12:50 . 2008-01-24 17:12 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-03-25 12:48 . 2008-01-24 17:22 -------- d-----w c:\program files\Google
2009-03-24 17:35 . 2008-01-24 14:07 94576 ----a-w c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-24 17:11 . 2008-01-24 14:13 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-24 16:58 . 2008-04-08 10:54 -------- d-----w c:\program files\Common Files\Adobe
2009-03-15 21:34 . 2009-03-15 21:34 -------- d-----w c:\documents and settings\All Users\Application Data\SweetIM
2009-03-15 21:34 . 2009-03-15 21:34 -------- d-----w c:\program files\SweetIM
2009-03-12 10:36 . 2009-03-12 10:36 -------- d-----w c:\documents and settings\user\Application Data\Avant Profiles
2009-03-12 10:36 . 2009-03-12 10:35 -------- d-----w c:\program files\Avant Browser
2009-03-09 23:06 . 2008-05-19 10:10 -------- d-----w c:\documents and settings\user\Application Data\Vso
2009-03-09 23:05 . 2008-05-19 10:10 81920 ----a-w c:\documents and settings\user\Application Data\ezpinst.exe
2009-03-09 23:05 . 2008-05-19 10:10 47360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2009-03-09 23:05 . 2008-05-19 10:10 47360 ----a-w c:\documents and settings\user\Application Data\pcouffin.sys
2009-03-09 20:24 . 2009-03-09 20:24 -------- d-----w c:\documents and settings\user\Application Data\Malwarebytes
2009-03-09 20:24 . 2009-03-09 20:24 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-03-09 20:24 . 2009-03-09 20:24 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-09 19:40 . 2008-02-27 13:32 -------- d-----w c:\program files\Any Video Converter Professional
2009-03-02 10:41 . 2009-03-01 08:22 -------- d-----w c:\program files\AskBarDis
2009-03-01 08:22 . 2009-03-01 08:22 -------- d-----w c:\program files\AskSearch
2009-03-01 08:21 . 2008-01-24 19:26 -------- d-----w c:\program files\Paltalk Messenger
2009-02-02 16:28 . 2009-02-02 16:28 2560 ----a-w c:\windows\_MSRSTRT.EXE
2008-08-11 03:34 . 2008-08-11 03:34 192200 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2008-01-25 12:47 . 2008-01-25 12:47 127 ----a-w c:\documents and settings\user\Local Settings\Application Data\fusioncache.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-8087-36EE87E26986}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AC7BD467-1714-44D7-923E-04B20C14E50A}]
2008-03-13 14:11 2371584 ----a-w c:\program files\FALCOM\FALCOM Arabic Toolbar\FalcomToolbarAr.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{5E96E27A-30C7-42E8-8747-E44B708C04E2}"= "c:\program files\FALCOM\FALCOM Arabic Toolbar\FalcomToolbarAr.dll" [2008-03-13 2371584]
[HKEY_CLASSES_ROOT\clsid\{5e96e27a-30c7-42e8-8747-e44b708c04e2}]
[HKEY_CLASSES_ROOT\TBSB01631.TBSB01631.3]
[HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}]
[HKEY_CLASSES_ROOT\TBSB01631.TBSB01631]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{5E96E27A-30C7-42E8-8747-E44B708C04E2}"= "c:\program files\FALCOM\FALCOM Arabic Toolbar\FalcomToolbarAr.dll" [2008-03-13 2371584]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
[HKEY_CLASSES_ROOT\clsid\{5e96e27a-30c7-42e8-8747-e44b708c04e2}]
[HKEY_CLASSES_ROOT\TBSB01631.TBSB01631.3]
[HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}]
[HKEY_CLASSES_ROOT\TBSB01631.TBSB01631]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2008-01-25 190024]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 1232896]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-03-28 1079296]
"KashifPro"="c:\documents and settings\user\KashifPro\KashifPro.exe" [2008-11-24 770048]
"way pop"="c:\docume~1\user\APPLIC~1\help 01 mapi\ACID BLAH.exe" [2009-02-07 630784]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2009-02-06 2356088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-06-13 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-06-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-06-13 118784]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-07-19 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-29 766041]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [2007-08-31 249896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"dupe amok gram atom"="c:\documents and settings\All Users\Application Data\Once Dog Dupe Amok\Meal owns.exe" [2009-04-21 786432]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-07-19 16248320]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-07-19 2879488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-1-17 618557]
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2009-1-28 10950144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=CLKERN.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^user^قائمة ابدأ^البرامج^بدء التشغيل^برنامج تداول للأعضاء.lnk]
path=c:\documents and settings\user\قائمة ابدأ\البرامج\بدء التشغيل\برنامج تداول للأعضاء.lnk
backup=c:\windows\pss\برنامج تداول للأعضاء.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"c:\\Program Files\\EPCTV\\Internet TV & Radio Player\\TVPlayer.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Online TV Player 4\\TVPlayer.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:UDP"= 443:UDP

oVoo UDP المنفذ 443
"37674:TCP"= 37674:TCP

oVoo TCP المنفذ 37674
"37674:UDP"= 37674:UDP

oVoo UDP المنفذ 37674
"37675:UDP"= 37675:UDP

oVoo UDP المنفذ 37675
"443:TCP"= 443:TCP

oVoo TCP المنفذ 443
"37676:TCP"= 37676:TCP

oVoo TCP المنفذ 37676
"37676:UDP"= 37676:UDP

oVoo UDP المنفذ 37676
"37677:UDP"= 37677:UDP

oVoo UDP المنفذ 37677
"37678:TCP"= 37678:TCP

oVoo TCP المنفذ 37678
"37678:UDP"= 37678:UDP

oVoo UDP المنفذ 37678
"37679:UDP"= 37679:UDP

oVoo UDP المنفذ 37679
R2 gupdate1c9ad47ffee0be6;خدمة تحديث Google (gupdate1c9ad47ffee0be6);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-25 133104]
S0 ML360Srv;ML360Srv; [x]
S2 AntiVirMailService;AntiVir PersonalEdition Premium MailGuard;c:\program files\Avira\AntiVir PersonalEdition Premium\avmailc.exe [2007-08-28 135208]
S2 AVEService;AntiVir PersonalEdition Premium MailGuard helper service;c:\program files\Avira\AntiVir PersonalEdition Premium\avesvc.exe [2007-07-18 12840]
.
Contents of the 'Scheduled Tasks' folder
2009-04-20 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-25 12:48]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-msnmsgr - ~c:\program files\MSN Messenger\msnmsgr.exe
HKCU-Run-SpeedItUpEX - c:\program files\SpeedItUpFree\SpeedItUp.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://home.sweetim.com
mStart Page = hxxp://home.sweetim.com
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct=&gc=1&q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Download All by FlashGet - c:\progra~1\FlashGet\jc_all.htm
IE: Download using FlashGet - c:\progra~1\FlashGet\jc_link.htm
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
LSP: avsda.dll
TCP: {30FFBE82-8788-4936-A10F-C2D829903EF7} = 213.165.32.134,213.165.32.137
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-21 11:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
msnmsgr = ~"c:\program files\MSN Messenger\msnmsgr.exe" /background?g
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-527237240-1965331169-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*t*t* \OpenWithList]
@Class="Shell"
"a"="msnmsgr.exe"
"MRUList"="a"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(900)
c:\windows\system32\CLKERN.DLL
- - - - - - - > 'lsass.exe'(956)
c:\windows\system32\CLKERN.DLL
c:\windows\system32\avsda.dll
.
Completion time: 2009-04-21 11:48
ComboFix-quarantined-files.txt 2009-04-21 08:48
Pre-Run: 29,310,468,096 bytes free
Post-Run: 30,269,562,880 bytes free
207 --- E O F --- 2008-02-13 23:57