ComboFix 08-03-24.2 - Noor 2008-03-25 12:58:26.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.315 [GMT 3:00]
Running from: C:\Documents and Settings\Noor\My Documents\Downloads\Programs\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\Cfx32.lic
C:\WINDOWS\system32\cfx32.ocx
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-25 to 2008-03-25 )))))))))))))))))))))))))))))))
.
2008-03-25 12:46 . 2008-03-25 12:50 <DIR> d-------- C:\Program Files\Your Uninstaller 2008
2008-03-25 12:46 . 2008-03-25 12:46 <DIR> d-------- C:\Documents and Settings\Noor\Application Data\URSoft
2008-03-25 12:46 . 2008-03-25 12:47 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-25 12:25 . 2008-03-25 12:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2008-03-24 08:32 . 2008-03-25 12:09 <DIR> d-------- C:\QUARANTINE
2008-03-24 08:26 . 2008-03-24 08:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-03-23 04:19 . 2008-03-23 04:19 16,244 --a------ C:\WINDOWS\system32\rrt_is.wav
2008-03-23 04:19 . 2008-03-23 04:19 7,302 --a------ C:\WINDOWS\system32\rrt_vf.wav
2008-03-23 04:19 . 2008-03-23 04:19 7,148 --a------ C:\WINDOWS\system32\rrt_tv.wav
2008-03-23 04:19 . 2008-03-23 04:19 6,282 --a------ C:\WINDOWS\system32\rrt_tn.wav
2008-03-23 01:27 . 2008-03-23 01:28 <DIR> d-------- C:\divx
2008-03-23 01:26 . 2008-03-23 01:31 <DIR> d-------- C:\Documents and Settings\Administrator.SAT\Application Data\DivX
2008-03-23 00:15 . 2008-03-23 00:15 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-23 00:15 . 2008-03-23 01:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-22 11:47 . 2008-03-22 11:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-03-22 11:46 . 2008-03-22 11:47 <DIR> d-------- C:\Program Files\Yahoo!
2008-03-20 10:03 . 2008-03-20 10:03 <DIR> d-------- C:\Documents and Settings\Noor\Application Data\DivX
2008-03-20 10:00 . 2008-03-20 10:02 <DIR> d-------- C:\Program Files\DivX
2008-03-16 08:42 . 2008-03-16 08:42 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-03-16 08:39 . 2008-03-16 08:39 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-03-16 08:36 . 2008-03-24 22:37 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-03-16 01:40 . 2008-03-21 15:37 <DIR> d-------- C:\Documents and Settings\sohaib\Application Data\IDM
2008-03-16 01:40 . 2008-03-25 12:50 <DIR> d-------- C:\Documents and Settings\sohaib\Application Data\DMCache
2008-03-15 22:46 . 2008-03-15 22:46 512 --a------ C:\ScanSectorLog.dat
2008-03-15 22:43 . 2008-03-15 22:43 <DIR> d-------- C:\Documents and Settings\Noor\Application Data\MailFrontier
2008-03-15 22:16 . 2007-03-09 00:02 75,512 --a------ C:\WINDOWS\zllsputility.exe
2008-03-15 22:16 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-03-15 22:16 . 2008-03-25 11:36 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-03-15 22:15 . 2008-03-25 12:10 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-03-15 22:15 . 2007-03-09 00:01 1,087,216 --a------ C:\WINDOWS\system32\zpeng24.dll
2008-03-15 22:15 . 2008-03-25 11:32 49,617 --a------ C:\WINDOWS\system32\vsconfig.xml
2008-03-15 22:09 . 2008-03-15 22:09 <DIR> d-------- C:\Program Files\Zone Labs
2008-03-15 20:47 . 2008-03-25 12:50 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-03-15 19:01 . 2008-03-16 16:23 <DIR> d-------- C:\Program Files\Internet Download Manager
2008-03-15 19:01 . 2008-03-18 21:59 <DIR> d-------- C:\Documents and Settings\Noor\Application Data\IDM
2008-03-15 19:01 . 2008-03-25 12:57 <DIR> d-------- C:\Documents and Settings\Noor\Application Data\DMCache
2008-03-15 18:21 . 2008-03-15 18:21 25,773 --a------ C:\WINDOWS\system32\drivers\regguard.sys
2008-03-15 12:41 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-15 12:41 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-15 04:26 . 2008-03-15 04:27 <DIR> d-------- C:\Program Files\Windows Live
2008-03-15 04:26 . 2008-03-15 04:27 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-15 04:26 . 2008-03-15 04:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-15 02:29 . 2008-03-15 02:29 7,168 --ahs---- C:\WINDOWS\Thumbs.db
2008-03-14 20:00 . 2008-03-14 20:00 <DIR> d-------- C:\Program Files\Real
2008-03-14 20:00 . 2008-03-14 20:00 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-03-14 19:59 . 2008-03-14 20:00 <DIR> d-------- C:\Program Files\Common Files\Real
2008-03-14 17:10 . 2004-08-04 10:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-03-14 16:23 . 2008-03-14 16:23 47,360 --a------ C:\WINDOWS\system32\drivers\Pcouffin.sys
2008-03-14 16:22 . 2008-03-14 16:23 <DIR> d-------- C:\Program Files\Video Convert Master
2008-03-14 16:22 . 2004-05-26 21:37 719,872 --a------ C:\WINDOWS\system32\devil.dll
2008-03-14 16:22 . 2006-09-16 19:44 314,368 --a------ C:\WINDOWS\system32\avisynth.dll
2008-03-14 11:51 . 2008-03-14 11:51 <DIR> d-------- C:\Documents and Settings\sohaib\Application Data\Nokia Multimedia Player
2008-03-14 04:58 . 2003-02-28 16:34 313,856 --a------ C:\WINDOWS\system32\dx3j.dll
2008-03-14 04:58 . 2003-02-28 18:26 171,792 --a------ C:\WINDOWS\system32\wjview.exe
2008-03-14 04:58 . 2003-02-28 18:26 171,280 --a------ C:\WINDOWS\system32\jit.dll
2008-03-14 04:58 . 2003-02-28 18:26 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2008-03-14 04:58 . 2003-02-28 18:26 46,352 --a------ C:\WINDOWS\setdebug.exe
2008-03-14 04:58 . 2003-02-28 16:54 7,315 --a------ C:\WINDOWS\system32\javasup.vxd
2008-03-14 04:58 . 2003-02-28 16:35 6,550 --a------ C:\WINDOWS\jautoexp.dat
2008-03-14 04:58 . 2003-02-28 16:38 113 --a------ C:\WINDOWS\system32\zonedon.reg
2008-03-14 04:58 . 2003-02-28 16:38 113 --a------ C:\WINDOWS\system32\zonedoff.reg
2008-03-14 04:57 . 2003-02-28 18:26 947,472 --a------ C:\WINDOWS\system32\msjava.dll
2008-03-14 04:57 . 2003-02-28 18:26 404,752 --a------ C:\WINDOWS\system32\javart.dll
2008-03-14 04:57 . 2003-02-28 18:26 286,992 --a------ C:\WINDOWS\system32\vmhelper.dll
2008-03-14 04:57 . 2003-02-28 18:26 187,152 --a------ C:\WINDOWS\system32\javacypt.dll
2008-03-14 04:57 . 2003-02-28 18:26 172,304 --a------ C:\WINDOWS\system32\jview.exe
2008-03-14 04:57 . 2003-02-28 18:26 154,384 --a------ C:\WINDOWS\system32\msawt.dll
2008-03-14 04:57 . 2003-02-28 18:26 63,248 --a------ C:\WINDOWS\system32\javaprxy.dll
2008-03-14 04:57 . 2003-02-28 18:26 49,424 --a------ C:\WINDOWS\system32\clspack.exe
2008-03-14 04:57 . 2003-02-28 18:26 21,264 --a------ C:\WINDOWS\system32\msjdbc10.dll
2008-03-14 04:57 . 2003-02-28 18:26 15,120 --a------ C:\WINDOWS\system32\jdbgmgr.exe
2008-03-14 03:28 . 2008-03-14 03:28 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-03-14 03:11 . 2008-03-25 06:31 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\SolidDocuments
2008-03-14 02:52 . 2008-03-14 02:52 268 --ah----- C:\sqmdata10.sqm
2008-03-14 02:52 . 2008-03-14 02:52 244 --ah----- C:\sqmnoopt10.sqm
2008-03-14 02:49 . 2008-03-14 02:49 <DIR> d-------- C:\WINDOWS\Sun
2008-03-14 02:39 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-14 02:38 . 2008-03-14 03:46 <DIR> d-------- C:\Program Files\Java
2008-03-14 02:19 . 2008-03-14 02:19 <DIR> d-------- C:\Program Files\Common Files\Java
2008-03-14 02:04 . 2006-07-22 23:49 5,376 --a------ C:\WINDOWS\system32\antiwpa.dll_1849C
2008-03-14 02:04 . 2005-08-12 05:25 5,376 --a------ C:\WINDOWS\system32\antiwpa.dll
2008-03-14 01:57 . 2008-03-14 01:57 123 --a------ C:\WINDOWS\rootkitno.ini
2008-03-14 01:26 . 2008-03-15 18:06 <DIR> d-------- C:\RootkitNO
2008-03-14 01:18 . 2008-03-14 01:18 30,946 --a------ C:\WINDOWS\system32\drivers\Partizan.sys
2008-03-14 01:18 . 2008-03-14 01:18 25,088 --a------ C:\WINDOWS\system32\Partizan.exe
2008-03-14 01:18 . 2005-04-03 14:02 8,944 --a------ C:\WINDOWS\system32\drivers\UnHackMeDrv.sys
2008-03-14 01:18 . C:\WINDOWS\(2) C:\ComboFix\winstart.bat
2008-03-14 01:17 . 2008-03-25 12:50 <DIR> d-------- C:\Program Files\UnHackMe
2008-03-14 00:31 . 2008-03-14 00:47 <DIR> d-------- C:\Program Files\XoftSpySE
2008-03-14 00:26 . 2008-03-14 00:26 268 --ah----- C:\sqmdata09.sqm
2008-03-14 00:26 . 2008-03-14 00:26 244 --ah----- C:\sqmnoopt09.sqm
2008-03-14 00:11 . 2008-03-14 00:11 268 --ah----- C:\sqmdata08.sqm
2008-03-14 00:11 . 2008-03-14 00:11 244 --ah----- C:\sqmnoopt08.sqm
2008-03-13 18:56 . 2008-03-13 18:58 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\SolidDocuments
2008-03-13 18:54 . 2008-03-13 18:54 268 --ah----- C:\sqmdata07.sqm
2008-03-13 18:54 . 2008-03-13 18:54 244 --ah----- C:\sqmnoopt07.sqm
2008-03-13 18:53 . 2008-03-13 18:53 <DIR> d--h----- C:\WINDOWS\PIF
2008-03-13 18:52 . 2008-03-13 18:52 266 --a------ C:\Documents and Settings\BaBa\Application Data\config.dat
2008-03-13 18:51 . 2008-03-13 18:51 268 --ah----- C:\sqmdata06.sqm
2008-03-13 18:51 . 2008-03-13 18:51 244 --ah----- C:\sqmnoopt06.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-14 17:00 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-03-14 17:00 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-03-14 01:58 155,995 ----a-w C:\WINDOWS\java\Packages\5BN3TN9F.ZIP
2008-03-04 18:37 344,064 ----a-w C:\WINDOWS\system32\dkll.dll
2008-03-04 18:37 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-03-04 18:37 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-03-04 18:37 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-03-02 22:59 --------- d-----w C:\Program Files\microsoft frontpage
2008-02-21 02:05 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-02-21 02:05 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-02-21 02:05 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-02-21 02:05 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-02-21 02:05 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-02-21 02:05 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-02-21 02:05 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-02-21 02:04 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-02-21 02:04 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-02-21 02:04 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-02-21 02:04 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-02-21 02:04 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-02-21 02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-02-21 02:04 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-02-21 02:04 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-02-21 02:03 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-21 02:03 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-02-15 15:12 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 10:56 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-02-21 13:59 937392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-28 12:51 218376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 10:56 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 10:17 1241088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
antiwpa.dll 2005-08-12 05:25 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\DOCUME~1]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\DOCUME~1\Noor]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\DOCUME~1\Noor\LOCALS~1]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\DOCUME~1\Noor\LOCALS~1\Temp]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\DOCUME~1\Noor\LOCALS~1\Temp\ir_ext_temp_1]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\DOCUME~1\Noor\LOCALS~1\Temp\ir_ext_temp_1\AutoPlay]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\DOCUME~1\Noor\LOCALS~1\Temp\ir_ext_temp_1\AutoPlay\Docs]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\DOCUME~1\Noor\LOCALS~1\Temp\ir_ext_temp_1\AutoPlay\Docs\Zyzoom_all_windows_Activation.com]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
S3 RegGuard;RegGuard;C:\WINDOWS\system32\Drivers\regguard.sys [2008-03-15 18:21]
.
*******s of the 'Scheduled Tasks' folder
"2008-03-25 07:46:03 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-03-13 15:08:19 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-03-25 07:46:03 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2008-03-25 00:04:05 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-03-25 13:00:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-25 13:00:56
ComboFix-quarantined-files.txt 2008-03-25 10:00:53
.
2008-03-16 00:50:32 --- E O F ---