ComboFix 09-06-07.01 - سمر 06/07/2009 22:33.3 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.382.224 [GMT 3:00]
Running from: c:\documents and settings\سمر\My Documents\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Avira\AntiVir Desktop\avsda.dll
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\kakle.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\winitn.dll
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
.
2009-06-06 18:33 . 2009-06-06 18:33 -------- d-sh--w- C:\FOUND.024
2009-06-06 10:44 . 2009-06-06 10:44 -------- d-sh--w- C:\FOUND.023
2009-06-06 10:35 . 2009-06-06 10:35 -------- d-----w- C:\zanti-adware
2009-06-05 20:22 . 2009-06-05 20:22 -------- d-----w- c:\documents and settings\سمر\Local Settings\Application Data\Deployment
2009-05-29 16:16 . 2009-05-29 16:16 98304 ----a-w- c:\documents and settings\سمر\Application Data\elefundesktops\fantasyworld_wallpaper\wallpaper.exe
2009-05-29 16:16 . 2009-05-29 16:16 57344 ----a-w- c:\documents and settings\سمر\Application Data\elefundesktops\fantasyworld_wallpaper\wallpaper.dll
2009-05-29 16:16 . 2009-05-29 16:16 1638404 ----a-w- c:\documents and settings\سمر\Application Data\elefundesktops\fantasyworld_wallpaper\swfplayer.exe
2009-05-29 16:16 . 2009-05-29 16:16 151552 ----a-w- c:\documents and settings\سمر\Application Data\elefundesktops\fantasyworld_wallpaper\sysinfo.exe
2009-05-29 16:16 . 2009-05-29 16:16 1153816 ----a-w- c:\documents and settings\سمر\Application Data\elefundesktops\fantasyworld_wallpaper\flash.exe
2009-05-29 16:16 . 2009-05-29 16:16 -------- d-----w- c:\documents and settings\سمر\Application Data\elefundesktops
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-07 19:36 . 2008-06-28 23:51 12 ----a-w- c:\windows\bthservsdp.dat
2009-05-02 16:29 . 2009-05-02 16:29 -------- d-----w- c:\program files\MessengerDiscovery
2009-04-27 10:32 . 2009-04-12 20:17 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-04-27 10:32 . 2009-04-12 20:17 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-04-26 13:26 . 2009-04-26 13:26 -------- d-----w- c:\documents and settings\سمر\Application Data\Avira
2009-04-12 20:17 . 2009-04-12 20:17 -------- d-----w- c:\program files\Avira
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 14:20 279944 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}]
2009-03-05 20:50 1883672 ----a-w- c:\program files\Peer2Peer-EN\tbPee0.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-10-08 09:22 1172792 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"EleFunAnimatedWallpaper"="c:\documents and settings\سمر\Application Data\elefundesktops\fantasyworld_wallpaper\wallpaper.exe" [2009-05-29 98304]
"Google Update"="c:\documents and settings\سمر\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-05 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk
backup=c:\windows\pss\BlueSoleil.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^سمر^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\سمر\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\System32\\USMT\\migwiz.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\groove.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Nero\\Nero ControlCenter\\SetupX.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\TeamViewer3\\TeamViewer.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/04/2009 11:17 م 108289]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [29/06/2008 08:12 م 194304]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [22/10/2008 10:36 م 714240]
S1 oxser;OX16C95x Serial port driver;c:\windows\system32\drivers\OXSER.SYS [30/06/2008 11:03 م 51169]
S2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [12/04/2009 11:17 م 194817]
S2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [12/04/2009 11:17 م 432897]
S3 DM9USB;DM9601 USB To Fast Ethernet Adapter;c:\windows\system32\drivers\dm9usb.sys [22/10/2008 10:49 م 21376]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Amazing3DAquariumWallpaper - (no file)
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uStart Page = hxxp://www.google.com.sa/
uInternet Settings,ProxyServer = 212.118.133.150:8080
FF - ProfilePath - c:\documents and settings\سمر\Application Data\Mozilla\Firefox\Profiles\qe775sne.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2004933&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/webhp?hl=ar
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct=&gc=1&q=
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-07 22:38
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(576)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\IVT CORPORATION\BLUESOLEIL\BTNTSERVICE.EXE
c:\program files\CYBERLINK\SHARED FILES\RICHVIDEO.EXE
c:\documents and settings\c:\documents and settings\c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-07 22:40 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-07 19:40
ComboFix2.txt 2008-07-06 00:11
ComboFix3.txt 2008-07-03 20:18
Pre-Run: 19,326,713,856 bytes free
Post-Run: 19,770,212,352 bytes free
162 --- E O F --- 2008-09-21 00:05