ComboFix 09-07-09.08 - ASUS 07/10/2009 18:23.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1256.966.1025.18.1015.606 [GMT 3:00]
Running from: c:\documents and settings\ASUS\My Documents\Downloads\Programs\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\p.exe
c:\recycler\S-1-5-21-531386931-3803073450-3954931842-1003
c:\windows\AhnRpta.exe
c:\windows\system32\e8main0.dll
c:\windows\system32\e8main1.dll
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\olhrwef.exe
D:\Autorun.inf
D:\metdgv.bat
D:\uo10sn.cmd
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
((((((((((((((((((((((((( Files Created from 2009-06-10 to 2009-07-10 )))))))))))))))))))))))))))))))
.
2010-02-04 11:06 . 2008-04-14 00:09 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2010-02-04 11:06 . 2008-04-14 00:16 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2010-02-04 11:06 . 2008-04-14 00:16 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2010-02-04 11:06 . 2008-04-14 00:16 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2010-02-04 11:06 . 2008-04-14 00:16 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2010-02-04 11:06 . 2008-04-14 00:16 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2010-02-04 11:06 . 2008-04-14 00:09 7552 ----a-w- c:\windows\system32\drivers\MSKSSRV.sys
2010-02-04 11:06 . 2008-04-14 00:09 5376 ----a-w- c:\windows\system32\drivers\MSPCLOCK.sys
2010-02-04 11:06 . 2008-04-14 00:16 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2010-02-04 11:06 . 2008-04-14 00:09 4992 ----a-w- c:\windows\system32\drivers\MSPQM.sys
2010-02-04 11:05 . 2001-08-17 13:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2010-02-04 11:05 . 2008-04-14 21:29 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2010-02-04 11:05 . 2008-04-14 18:29 4096 -c--a-w- c:\windows\system32\dllcache\ksuser.dll
2010-02-04 11:05 . 2008-04-14 18:29 4096 ----a-w- c:\windows\system32\ksuser.dll
2010-02-04 11:05 . 2008-04-14 00:16 121984 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-02-04 11:05 . 2008-04-14 21:07 57472 ----a-w- c:\windows\system32\drivers\redbook.sys
2010-02-04 11:04 . 2008-04-14 00:06 10240 ----a-w- c:\windows\system32\drivers\compbatt.sys
2010-02-04 11:04 . 2008-04-14 21:05 16384 ----a-w- c:\windows\system32\drivers\battc.sys
2010-02-04 11:04 . 2008-04-14 00:06 13952 ----a-w- c:\windows\system32\drivers\CmBatt.sys
2010-02-04 11:04 . 2008-04-14 18:29 73728 -c--a-w- c:\windows\system32\dllcache\usbui.dll
2010-02-04 11:04 . 2008-04-14 18:29 73728 ----a-w- c:\windows\system32\usbui.dll
2010-02-04 11:01 . 2009-07-10 15:25 -------- d-----w- c:\windows\system32\CatRoot2
2010-02-04 11:01 . 2009-07-08 16:40 -------- d-----w- c:\windows\system32\CatRoot
2010-02-04 11:01 . 2010-02-04 08:10 -------- d-----w- c:\documents and settings\All Users
2010-02-04 11:01 . 2009-07-02 20:15 -------- d-----w- C:\Documents and Settings
2010-02-04 11:01 . 2009-07-02 20:15 -------- d--h--w- c:\documents and settings\Default User
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-04 10:53 . 2010-02-04 10:53 -------- d-----w- c:\program files\Atheros
2010-02-04 10:53 . 2010-02-04 10:18 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-04 10:53 . 2010-02-04 10:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Atheros
2010-02-04 10:52 . 2010-02-04 10:52 -------- d-----w- c:\program files\Elantech
2010-02-04 10:38 . 2010-02-04 10:38 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-02-04 10:37 . 2010-02-04 10:37 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-02-04 10:36 . 2010-02-04 10:36 -------- d-----w- c:\program files\Microsoft
2010-02-04 10:36 . 2010-02-04 10:36 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-02-04 10:34 . 2010-02-04 10:34 -------- d-----w- c:\program files\Common Files\Windows Live
2010-02-04 10:33 . 2010-02-04 10:33 -------- d-----w- c:\program files\Windows Media Connect 2
2010-02-04 10:31 . 2010-02-04 10:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-02-04 10:31 . 2010-02-04 10:30 -------- d-----w- c:\program files\Eee Storage
2010-02-04 10:25 . 2010-02-04 10:25 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-04 10:24 . 2010-02-04 10:23 -------- d-----w- c:\program files\ASUS
2010-02-04 10:24 . 2010-02-04 10:18 -------- d-----w- c:\program files\Common Files\InstallShield
2010-02-04 10:22 . 2010-02-04 10:22 -------- d-----w- c:\program files\WIDCOMM
2010-02-04 10:21 . 2010-02-04 10:21 -------- d-----w- c:\program files\RALINK
2010-02-04 10:21 . 2010-02-04 10:21 -------- d-----w- c:\program files\EeePC
2010-02-04 10:20 . 2009-07-02 20:15 -------- d-----w- c:\documents and settings\ASUS\Application Data\InstallShield
2010-02-04 10:20 . 2009-07-02 20:15 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\InstallShield
2010-02-04 10:19 . 2010-02-04 10:19 -------- d-----w- c:\program files\Intel
2010-02-04 10:18 . 2010-02-04 10:18 -------- d-----w- c:\program files\Realtek
2010-02-04 10:18 . 2010-02-04 10:18 319488 ----a-w- c:\windows\HideWin.exe
2010-02-04 08:31 . 2010-02-04 08:10 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-02-04 08:11 . 2010-02-04 08:11 -------- d-----w- c:\program files\microsoft frontpage
2010-02-04 08:09 . 2010-02-04 08:09 22144 ----a-w- c:\windows\system32\emptyregdb.dat
2009-07-10 15:29 . 2009-07-06 10:33 -------- d-----w- c:\documents and settings\ASUS\Application Data\DMCache
2009-07-10 10:25 . 2010-02-04 17:54 63626 ----a-w- c:\windows\system32\perfc001.dat
2009-07-10 10:25 . 2010-02-04 17:54 340142 ----a-w- c:\windows\system32\perfh001.dat
2009-07-10 02:49 . 2009-07-10 02:44 254106 ----a-w- c:\documents and settings\ASUS\Application Data\IDM\DwnlData\ASUS\ComboFix_81\ComboFix.exe
2009-07-09 02:58 . 2009-07-04 23:34 -------- d-----w- c:\documents and settings\ASUS\Application Data\U3
2009-07-09 02:25 . 2009-07-09 02:26 24433136 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9F59C3AE-81B0-4EF6-9762-D674BB079705}\NokiaSoftwareUpdaterSetup_ar_2.exe
2009-07-09 01:47 . 2009-07-09 01:47 -------- d-----w- c:\program files\Common Files\Nokia
2009-07-09 01:47 . 2009-07-09 01:46 -------- d-----w- c:\program files\Common Files\PCSuite
2009-07-09 01:47 . 2009-07-06 19:17 -------- d-----w- c:\program files\Nokia
2009-07-09 01:38 . 2009-07-09 01:38 -------- d-----w- c:\program files\Trend Micro
2009-07-08 17:11 . 2009-07-08 15:46 -------- d-----w- c:\program files\Google
2009-07-08 16:17 . 2009-07-08 16:17 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9F59C3AE-81B0-4EF6-9762-D674BB079705}\Installer\CommonCustomActions\msxml6Exec.exe
2009-07-08 16:17 . 2009-07-08 16:17 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9F59C3AE-81B0-4EF6-9762-D674BB079705}\Installer\CommonCustomActions\Sleep.exe
2009-07-08 16:17 . 2009-07-08 16:17 3181612 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9F59C3AE-81B0-4EF6-9762-D674BB079705}\Installer\CommonCustomActions\vcredistExec.exe
2009-07-08 16:16 . 2009-07-08 16:17 24433136 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9F59C3AE-81B0-4EF6-9762-D674BB079705}\NokiaSoftwareUpdaterSetup_ar.exe
2009-07-08 15:50 . 2009-07-02 21:08 -------- d-----w- c:\program files\Common Files\Real
2009-07-08 15:49 . 2009-07-08 15:49 -------- d-----w- c:\program files\Common Files\xing shared
2009-07-08 15:49 . 2009-07-02 21:08 -------- d-----w- c:\program files\Real
2009-07-08 05:17 . 2010-02-04 10:36 -------- d-----w- c:\program files\Windows Live
2009-07-08 02:46 . 2009-07-08 02:46 4096 ----a-w- c:\windows\d3dx.dat
2009-07-08 02:07 . 2009-07-06 10:33 -------- d-----w- c:\documents and settings\ASUS\Application Data\IDM
2009-07-07 23:26 . 2009-07-07 23:24 2927168 ----a-w- c:\documents and settings\ASUS\Application Data\IDM\idmupdt.exe
2009-07-07 22:37 . 2009-07-07 22:37 -------- d-----w- c:\documents and settings\ASUS\Application Data\ESET
2009-07-07 22:35 . 2009-07-07 22:35 -------- d-----w- c:\program files\ESET
2009-07-07 22:35 . 2009-07-07 22:35 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-07-07 17:28 . 2009-07-07 17:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-07-07 16:09 . 2009-07-06 19:21 107332 --sh--r- C:\q1alx.exe
2009-07-07 00:54 . 2009-07-06 19:18 -------- d-----w- c:\documents and settings\ASUS\Application Data\PC Suite
2009-07-07 00:36 . 2009-07-06 23:51 -------- d-----w- c:\documents and settings\ASUS\Application Data\Nokia
2009-07-07 00:17 . 2009-07-07 00:17 -------- d-----w- c:\documents and settings\ASUS\Application Data\Datalayer
2009-07-06 23:50 . 2009-07-06 19:18 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-07-06 19:19 . 2009-07-06 19:19 -------- d-----w- c:\program files\DIFX
2009-07-06 18:29 . 2009-07-05 20:59 111059 --sh--r- C:\aphqg.exe
2009-07-06 10:33 . 2009-07-06 10:33 198064 ----a-w- c:\documents and settings\ASUS\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-07-06 10:31 . 2009-07-06 10:31 -------- d-----w- c:\program files\Internet Download Manager
2009-07-06 00:59 . 2009-07-02 20:15 99104 ----a-w- c:\documents and settings\ASUS\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-05 18:49 . 2009-07-05 18:49 -------- d-----w- c:\program files\Microsoft Works
2009-07-05 18:45 . 2009-07-05 18:45 -------- d-----w- c:\program files\Microsoft.NET
2009-07-05 00:15 . 2009-07-05 00:15 -------- d-----w- c:\program files\MSECache
2009-07-04 23:50 . 2009-07-02 21:01 -------- d-----w- c:\program files\Yahoo!
2009-07-04 23:34 . 2009-07-04 23:35 109472 --sh--r- C:\9kretct.exe
2009-07-02 21:08 . 2003-03-18 17:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-07-02 21:02 . 2009-07-02 21:02 -------- d-----w- c:\program files\Common Files\BitDefender
2009-07-02 21:01 . 2009-07-02 21:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-07-02 20:57 . 2009-07-02 20:57 -------- d-----w- c:\program files\mpegable
2009-07-02 20:57 . 2009-07-02 20:57 45568 ------w- c:\windows\AKDeInstall.exe
2009-07-02 20:56 . 2009-07-02 20:56 -------- d-----w- c:\program files\Any Video Converter
2009-07-02 20:56 . 2009-07-02 20:56 -------- d-----w- c:\program files\Webteh
2009-07-02 20:56 . 2009-07-02 20:56 -------- d-----w- c:\documents and settings\ASUS\Application Data\Any Video Converter
2009-07-02 20:56 . 2009-07-02 20:56 -------- d-----w- c:\program files\Any Audio Converter
2009-07-02 20:16 . 2009-07-02 20:15 127 ----a-w- c:\documents and settings\ASUS\Local Settings\Application Data\fusioncache.dat
2009-07-02 15:44 . 2009-07-04 23:34 106352 --sh--r- C:\cj1m.com
2008-05-07 08:34 . 2010-02-04 10:26 15523560 ----a-w- c:\program files\U1 Setup.exe
2008-04-15 12:00 . 2010-02-04 17:54 168371 --sha-r- c:\windows\system32\upxqfoc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-06-27 2799024]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-12-04 114688]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-12-17 622592]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-20 94208]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2008-11-24 329728]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-10-24 1451264]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-07-08 198160]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-27 2658304]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-09-18 16855040]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-2 604776]
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2010-2-4 376832]
«©م، ¢¬نïé Adobe Reader.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5880:TCP"= 5880:TCP:vbces
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21/12/2007 11:21 ص 468224]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [04/02/2010 01:21 م 10752]
R3 Ktp;Elantech Smart-Pad;c:\windows\system32\drivers\ETD.sys [01/08/2008 05:24 ص 25216]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [04/11/2008 12:28 م 38400]
S2 BDVEDISK;BDVEDISK;\??\c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys --> c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [?]
S2 tzsnnjzqo;Boot Helper;c:\windows\system32\svchost.exe -k netsvcs [04/02/2010 08:54 م 14336]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
tzsnnjzqo
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Connection Wizard,ShellNext = hxxp://shell.windows.com/fileassoc/fileassoc.asp?LangID=0401&Ext=rar
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: إرسال إلى &جهاز Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: إرسال إلى Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-10 18:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tzsnnjzqo]
"ServiceDll"="c:\windows\system32\upxqfoc.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2204)
c:\windows\system32\btmmhook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\windows\system32\ConnAPI.DLL
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_ara.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
c:\progra~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
c:\program files\Internet Download Manager\IEMonitor.exe
c:\program files\Common Files\PCSuite\Services\NclBTHandler.exe
.
**************************************************************************
.
Completion time: 2009-07-10 18:31 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-10 15:31
Pre-Run: 79,794,065,408 bytes free
Post-Run: 79,988,670,464 bytes free
246