ComboFix 09-05-14.03 - mag 05/15/2009 7:30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.1014.581 [GMT 3:00]
Running from: c:\documents and settings\mag\My Documents\Downloads\Programs\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\mag\Application Data\.#
c:\windows\IE4 Error Log.txt
c:\windows\system32\kakle.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2009-04-15 to 2009-05-15 )))))))))))))))))))))))))))))))
.
2009-05-15 04:30 . 2009-05-15 04:30 -------- d-----w c:\documents and settings\mag\Local Settings\Application Data\ESET
2009-05-15 04:25 . 2009-05-15 04:25 -------- d-----w c:\documents and settings\mag\Application Data\ESET
2009-05-15 04:24 . 2009-05-15 04:24 -------- d-----w c:\program files\ESET
2009-05-15 04:12 . 2008-03-09 13:02 81632 ----a-w c:\windows\system32\FLKill.exe
2009-05-15 04:12 . 2004-05-10 09:42 110592 ----a-w c:\windows\system32\suppdll.dll
2009-05-15 04:12 . 2009-05-15 04:12 35363 ----a-w c:\windows\system32\windrvNT.sys
2009-05-15 04:12 . 2009-05-15 04:14 -------- d-----w c:\program files\Folder Lock
2009-05-15 03:36 . 2009-05-15 03:36 -------- d-----w c:\program files\Microsoft Windows OneCare Live
2009-05-15 02:58 . 2009-05-15 02:58 -------- d-----w c:\program files\Microsoft Sync Framework
2009-05-15 01:59 . 2009-05-15 01:59 -------- d-----w c:\documents and settings\mag\Application Data\QuickScan
2009-05-15 00:18 . 2009-05-15 00:18 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-05-15 00:15 . 2009-05-15 01:13 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-05-14 22:54 . 2009-05-14 22:55 -------- d-----w C:\$WIN_NT$.~BT
2009-05-14 19:55 . 2009-02-09 11:22 2190592 -c----w c:\windows\system32\dllcache\ntoskrnl.exe
2009-05-14 19:55 . 2009-02-09 11:22 2146816 -c----w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-05-14 19:55 . 2009-02-09 11:22 2025472 -c----w c:\windows\system32\dllcache\ntkrpamp.exe
2009-05-14 19:23 . 2008-06-14 17:31 271616 -c----w c:\windows\system32\dllcache\bthport.sys
2009-05-14 19:23 . 2008-06-14 17:31 271616 ------w c:\windows\system32\drivers\bthport.sys
2009-05-14 19:18 . 2008-10-24 11:21 455296 -c----w c:\windows\system32\dllcache\mrxsmb.sys
2009-05-12 20:09 . 2009-05-12 20:09 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-05-12 19:44 . 2009-05-12 19:44 -------- d-----w c:\documents and settings\mag\Application Data\vlc
2009-05-12 19:44 . 2009-05-12 19:44 -------- d-----w c:\documents and settings\mag\Application Data\Media Player Classic
2009-05-12 19:36 . 2009-05-12 20:22 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-12 17:18 . 2009-05-12 17:18 -------- d-----w c:\documents and settings\mag\Application Data\CyberScrub
2009-05-12 17:17 . 2009-05-12 17:17 -------- d-----w c:\documents and settings\mag\Application Data\cleaner
2009-05-12 13:03 . 2008-10-16 11:06 208744 ----a-w c:\windows\system32\muweb.dll
2009-05-12 13:03 . 2008-10-16 11:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-05-12 04:22 . 2009-05-15 01:47 -------- d-----w c:\program files\Windows Live Safety Center
2009-05-12 04:18 . 2009-05-12 04:18 -------- d-----w c:\documents and settings\mag\Application Data\IObit
2009-05-12 04:18 . 2009-05-12 04:18 -------- d-----w c:\program files\IObit
2009-05-12 03:47 . 1995-07-31 11:44 212480 ------w c:\windows\system32\PCDLIB32.DLL
2009-05-12 03:47 . 1995-07-11 07:50 24576 ------w c:\windows\system32\AWCODC32.DLL
2009-05-12 03:47 . 1995-07-11 07:50 26624 ------w c:\windows\system32\AWRESX32.DLL
2009-05-12 03:47 . 1995-10-09 14:58 10240 ------w c:\windows\system32\AWVIEW32.DLL
2009-05-12 03:47 . 1995-07-11 07:50 6144 ------w c:\windows\system32\AWDCXC32.DLL
2009-05-12 03:47 . 1995-11-16 16:39 11776 ------w c:\windows\system32\AWDENC32.DLL
2009-05-12 02:03 . 2009-05-12 02:03 0 ----a-w c:\windows\system32\cd.dat
2009-05-12 00:47 . 2009-05-15 04:34 -------- d-----w c:\documents and settings\mag\Tracing
2009-05-12 00:45 . 2009-05-12 00:45 -------- d-----w c:\program files\Microsoft
2009-05-12 00:45 . 2009-05-12 00:45 -------- d-----w c:\program files\Windows Live SkyDrive
2009-05-12 00:20 . 2009-05-12 00:20 -------- d-----w c:\documents and settings\mag\Local Settings\Application Data\Downloaded Installations
2009-05-12 00:14 . 2009-05-12 00:30 1004 --sha-w c:\windows\system32\sys_drv.dat
2009-05-11 23:34 . 2009-05-11 23:34 -------- d-----w c:\program files\VS Revo Group
2009-05-11 23:31 . 2009-05-12 00:20 -------- d-----w c:\windows\system32\Adobe
2009-05-11 23:29 . 2009-05-11 23:29 -------- d-----w c:\windows\Sun
2009-05-11 23:29 . 2009-05-11 23:29 410984 ----a-w c:\windows\system32\deploytk.dll
2009-05-11 23:29 . 2009-05-11 23:29 -------- d-----w c:\program files\Java
2009-05-11 23:15 . 2009-05-15 01:57 -------- d-----w C:\arabirc73
2009-05-11 21:55 . 2009-05-11 21:55 -------- d-----w c:\documents and settings\mag\Application Data\GRETECH
2009-05-11 21:34 . 2009-05-11 21:53 -------- d-----w c:\windows\SxsCaPendDel
2009-05-11 21:12 . 2009-05-14 21:10 -------- d-----w c:\documents and settings\mag\Application Data\IDM
2009-05-11 21:12 . 2009-05-15 01:48 -------- d-----w c:\program files\Internet Download Manager
2009-05-11 20:58 . 2009-05-11 20:58 -------- d-----w c:\program files\Common Files\Windows Live
2009-05-11 20:20 . 2009-05-15 01:49 -------- d-----w c:\documents and settings\mag\Application Data\Xfire
2009-05-11 20:19 . 2009-05-15 01:48 -------- d-----w c:\program files\GameSpy Arcade
2009-05-11 20:18 . 2009-05-11 20:18 -------- d-----w c:\documents and settings\mag\Application Data\COWON
2009-05-11 20:10 . 2009-05-11 20:10 -------- d-sh--w c:\documents and settings\mag\IECompatCache
2009-05-11 20:10 . 2009-05-11 20:10 -------- d-sh--w c:\documents and settings\mag\PrivacIE
2009-05-11 20:09 . 2009-05-11 20:09 -------- d-sh--w c:\documents and settings\mag\IETldCache
2009-05-11 20:07 . 2009-05-11 20:07 -------- d-----w c:\program files\Common Files\xing shared
2009-05-11 20:04 . 2009-05-11 20:04 -------- d-----w c:\windows\ie8updates
2009-05-11 20:02 . 2009-05-11 20:03 -------- dc-h--w c:\windows\ie8
2009-05-11 20:01 . 2009-04-25 05:30 102400 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-05-11 20:00 . 2009-05-11 20:00 -------- d-----w c:\program files\Windows Installer 4.5 SDK
2009-05-11 19:51 . 2009-05-11 19:56 -------- d-----w c:\windows\system32\ar
2009-05-11 19:51 . 2009-05-11 20:09 -------- d-----w c:\windows\system32\ar-sa
2009-05-11 19:51 . 2009-05-11 19:57 -------- d-----w c:\windows\L2Schemas
2009-05-11 19:44 . 2009-05-14 22:07 -------- d--h--w c:\windows\$hf_mig$
2009-05-11 19:42 . 2009-05-11 20:10 -------- d-----w c:\documents and settings\mag\Local Settings\Application Data\Google
2009-05-11 19:42 . 2009-05-15 04:30 -------- d-----w c:\documents and settings\mag\Application Data\DMCache
2009-05-11 19:41 . 2009-05-11 19:45 -------- d-----w c:\program files\Google
2009-05-11 19:41 . 2008-09-28 19:00 439440 ----a-w c:\program files\un_Internet Download Manager_16575.exe
2009-05-11 19:09 . 2009-05-12 00:47 27848 ----a-w c:\documents and settings\mag\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-11 18:35 . 2009-05-11 18:35 -------- d-----w c:\program files\EA GAMES
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-15 04:27 . 2002-08-29 09:30 40316 ----a-w c:\windows\system32\perfc001.dat
2009-05-15 04:27 . 2002-08-29 09:30 251946 ----a-w c:\windows\system32\perfh001.dat
2009-05-15 02:59 . 2009-05-11 15:11 -------- d-----w c:\program files\Windows Live
2009-05-15 01:48 . 2009-05-11 17:26 -------- d-----w c:\program files\Hotspot Shield
2009-05-15 01:48 . 2009-05-11 15:12 -------- d-----w c:\program files\JetAudio
2009-05-11 21:12 . 2009-05-11 19:41 5969 ----a-w c:\program files\un_Internet Download Manager_16575.txt
2009-05-11 20:07 . 2009-05-11 15:09 -------- d-----w c:\program files\Common Files\Real
2009-05-11 20:07 . 2009-05-11 15:09 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-05-11 20:07 . 2009-05-11 15:09 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-05-11 19:42 . 2009-05-11 15:09 -------- d-----w c:\program files\Real
2009-05-11 18:35 . 2009-05-11 15:12 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-11 17:10 . 2009-05-11 14:51 23380 ----a-w c:\windows\system32\emptyregdb.dat
2009-05-11 16:26 . 2009-05-11 16:26 -------- d-----w c:\program files\Marvell
2009-05-11 16:26 . 2009-05-11 15:13 -------- d-----w c:\program files\Common Files\InstallShield
2009-05-11 16:23 . 2009-05-11 16:23 -------- d-----w c:\program files\SigmaTel
2009-05-11 16:20 . 2009-05-11 16:20 -------- d-----w c:\program files\Intel
2009-05-11 16:18 . 2009-05-11 16:18 -------- d-----w c:\program files\Broadcom
2009-05-11 16:17 . 2009-05-11 16:17 -------- d-----w c:\program files\CONEXANT
2009-05-11 16:12 . 2009-05-11 16:12 -------- d-----w c:\program files\DIFX
2009-05-11 16:09 . 2009-05-11 16:09 -------- d-----w c:\program files\WIDCOMM
2009-05-11 15:13 . 2009-05-11 15:13 -------- d-----w c:\program files\CyberLink
2009-05-11 15:13 . 2009-05-11 15:13 90112 ----a-w c:\windows\system32\agsaami.dll
2009-05-11 15:13 . 2009-05-11 15:13 610304 ----a-w c:\windows\system32\agsaamg.dll
2009-05-11 15:13 . 2009-05-11 15:13 2535424 ----a-w c:\windows\system32\agsaamj.dll
2009-05-11 15:13 . 2009-05-11 15:13 1986560 ----a-w c:\windows\system32\akll.dll
2009-05-11 15:13 . 2009-05-11 15:13 196608 ----a-w c:\windows\system32\maag.dll
2009-05-11 15:13 . 2009-05-11 15:13 1245184 ----a-w c:\windows\system32\bkll.dll
2009-05-11 15:13 . 2009-05-11 15:13 1212416 ----a-w c:\windows\system32\ckll.dll
2009-05-11 15:13 . 2009-05-11 15:13 372736 ----a-w c:\windows\system32\agsaamc.dll
2009-05-11 15:12 . 2009-05-11 15:12 -------- d-----w c:\program files\Common Files\COWON
2009-05-11 15:11 . 2009-05-11 15:11 -------- d-----w c:\program files\VideoLAN
2009-05-11 15:11 . 2009-05-11 15:11 -------- d-----w c:\program files\GRETECH
2009-05-11 15:11 . 2009-05-11 15:10 -------- d-----w c:\program files\K-Lite Codec Pack
2009-05-11 15:06 . 2009-05-11 15:06 27264 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-11 14:54 . 2009-05-11 14:54 -------- d-----w c:\program files\microsoft frontpage
2009-04-03 18:18 . 2009-04-03 18:18 33256 ----a-w c:\windows\system32\drivers\HssDrv.sys
2009-03-26 15:35 . 2009-05-07 07:42 210352 ----a-w c:\windows\system32\idmmbc.dll
2009-03-08 01:34 . 2008-04-14 10:29 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 01:34 . 2008-04-14 10:29 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 01:33 . 2008-04-14 10:29 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 01:33 . 2008-04-14 10:29 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 01:32 . 2008-04-14 10:29 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 01:32 . 2008-04-14 10:29 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 01:31 . 2008-04-14 10:29 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 01:31 . 2008-04-14 10:05 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 01:31 . 2008-04-14 10:29 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 01:22 . 2001-09-19 14:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:20 . 2008-04-14 10:29 283136 ----a-w c:\windows\system32\pdh.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-05-12 02:03 218160 ----a-w c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-11 39408]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-05-11 2876848]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-05-16 137752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-16 162328]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-05-16 137752]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-11 198160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-11 148888]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-02-06 2021400]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2007-05-06 405504]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\MsiExec.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"= c:\\Program Files\\Real\\RealPlayer\\realplay.exe
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\igfxsrvc.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\WINDOWS\\stsystra.exe"=
"c:\\Program Files\\Internet Download Manager\\IEMonitor.exe"=
"c:\\arabirc73\\mirc32.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\WINDOWS\\system32\\igfxpers.exe"=
"c:\\PROGRA~1\\GRETECH\\GOMPLA~1\\GOM.exe"=
"c:\\Program Files\\Hotspot Shield\\bin\\openvpntray.exe"=
"c:\\Program Files\\Hotspot Shield\\bin\\openvpn.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2/6/2009 2:23 م 106208]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2/6/2009 2:23 م 727720]
R2 HssSrv;Hotspot Shield Helper Service;c:\program files\Hotspot Shield\HssWPR\hsssrv.exe [4/22/2009 4:12 ص 328752]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [1/14/2009 5:53 م 226656]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [5/11/2009 7:26 م 108032]
S3 HssTrayService;Hotspot Shield Tray Service;c:\program files\Hotspot Shield\bin\HssTrayService.exe [4/23/2009 12:34 ص 34352]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-05-12 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-05-12 15:15]
.
.
------- Supplementary Scan -------
.
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
LSP: xfire_lsp_9028.dll
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-15 07:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1692)
c:\windows\system32\xfire_lsp_9028.dll
- - - - - - - > 'explorer.exe'(3700)
c:\windows\system32\ieframe.dll
c:\program files\Internet Download Manager\idmmkb.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\igfxsrvc.exe
c:\program files\WIDCOMM\Bluetooth Software\BTStackServer.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\stacsv.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2009-05-15 7:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-15 04:37
Pre-Run: 41,854,750,720 bytes free
Post-Run: 42,055,364,608 bytes free
250 --- E O F --- 2009-05-14 22:07