[CENTER]ComboFix 08-06-20.4 - Abeer$ 06/28/2008 18:08:26.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.1565 [GMT 2:00]
Running from: C:\Documents and Settings\Abeer$\Desktop\ComboFix.exe
* Created a new restore point
[COLOR=red][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.
((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-28 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-28 16:09 --------- d-----w C:\Documents and Settings\Abeer$\Application Data\Free Download Manager
2008-06-28 16:04 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-06-28 16:02 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-28 15:33 --------- d-----w C:\Program Files\Java
2008-06-28 15:33 --------- d-----w C:\Program Files\Common Files\Java
2008-06-28 15:22 --------- d-----w C:\Program Files\Intel
2008-06-28 15:17 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-28 12:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\TechSmith
2008-06-28 12:10 --------- d-----w C:\Program Files\TechSmith
2008-06-28 12:10 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-28 12:06 --------- d-----w C:\Documents and Settings\Abeer$\Application Data\Media Player Classic
2008-06-28 12:03 --------- d-----w C:\Documents and Settings\Abeer$\Application Data\ACD Systems
2008-06-28 12:01 9,856 ----a-w C:\WINDOWS\system32\drivers\pfc.sys
2008-06-28 12:01 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-06-28 12:01 --------- d-----w C:\Program Files\ACD Systems
2008-06-28 12:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-06-28 11:40 --------- d-----w C:\Documents and Settings\Abeer$\Application Data\Paltalk
2008-06-28 11:22 --------- d-----w C:\Program Files\RegDoctor
2008-06-28 11:21 --------- d-----w C:\Program Files\PConPoint
2008-06-28 11:15 --------- d-----w C:\Program Files\Avira
2008-06-28 11:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-06-28 11:14 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-28 11:13 --------- d-----w C:\Program Files\Yahoo!
2008-06-28 11:13 --------- d-----w C:\Program Files\MSN Messenger
2008-06-28 11:13 --------- d-----w C:\Program Files\CCleaner
2008-06-28 11:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-06-28 11:12 --------- d-----w C:\Program Files\Real
2008-06-28 11:11 203,776 ----a-w C:\WINDOWS\system32\clrviddc.dll
2008-06-28 11:11 --------- d-----w C:\Program Files\Windows Live
2008-06-28 11:11 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-06-28 11:11 --------- d-----w C:\Program Files\Circle Developement
2008-06-28 11:10 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-06-28 11:10 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-28 11:10 --------- d-----w C:\Program Files\Common Files\xing shared
2008-06-28 11:10 --------- d-----w C:\Program Files\Common Files\Real
2008-06-28 11:09 --------- d-----w C:\Program Files\Paltalk Messenger
2008-06-28 11:02 --------- d-----w C:\Program Files\IDT
2008-06-28 10:53 --------- d-----w C:\Program Files\ma-config.com
2008-06-28 10:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-06-28 10:49 --------- d-----w C:\Program Files\Free Download Manager
2008-06-28 10:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
2008-06-28 10:49 --------- d-----w C:\Documents and Settings\Abeer$\Application Data\Software Informer
2008-06-28 10:30 --------- d-----w C:\Program Files\Your Uninstaller 2008
2008-06-28 10:30 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-06-28 10:29 --------- d-----w C:\Documents and Settings\Abeer$\Application Data\URSoft
2008-06-28 10:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-28 10:04 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-28 09:58 --------- d-----w C:\Program Files\RocketDock
2008-06-28 09:58 --------- d-----w C:\Program Files\Company
2008-06-28 09:56 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-05-07 12:16 1,271,032 ----a-w C:\WINDOWS\system32\drivers\sthda.sys
2008-05-07 12:14 212,992 ----a-w C:\WINDOWS\system32\stacsv.exe
2008-05-07 12:13 372,736 ----a-w C:\WINDOWS\system32\stacapi.dll
2008-05-07 12:13 164,352 ----a-w C:\WINDOWS\system32\staco.dll
2008-05-07 12:12 2,129,920 ----a-w C:\WINDOWS\system32\stlang.dll
2008-05-01 14:35 53,248 ----a-w C:\WINDOWS\system32\CSVer.dll
2008-04-10 22:25 25,088 ----a-w C:\WINDOWS\system32\msxml3a.dll
2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\divx.dll
2008-03-31 09:04 1,301,040 ----a-w C:\WINDOWS\system32\ncscolib.dll
2008-03-28 17:41 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
.
------- Sigcheck -------
01/26/2008 05:57 AM 14336 a9e050d11d430cde3c217a230835142e C:\WINDOWS\system32\svchost.exe
01/26/2008 05:57 AM 578560 a6f843fd642352eebbd73ccaa32e4f1a C:\WINDOWS\system32\user32.dll
01/26/2008 05:57 AM 82432 481c43e06fc751aecf422108abddbf22 C:\WINDOWS\system32\ws2_32.dll
04/21/2008 08:44 AM 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\SoftwareDistribution\Download\4a70167257b9ec465806ced7f92b65d8\sp3gdr\wininet.dll
04/21/2008 08:24 AM 666624 26f240c250e5b4b395cb4b178ba75437 C:\WINDOWS\SoftwareDistribution\Download\4a70167257b9ec465806ced7f92b65d8\sp3qfe\wininet.dll
01/26/2008 05:57 AM 666112 5390fbe8b096ef3fdfe1c06455a0d66d C:\WINDOWS\system32\wininet.dll
01/25/2008 11:10 PM 361344 b85d78274a1780c9ae5c02a2094e9596 C:\WINDOWS\system32\drivers\tcpip.sys
01/26/2008 05:58 AM 507904 7c87833890a151e4c88c086797ef1d98 C:\WINDOWS\system32\winlogon.exe
01/25/2008 11:11 PM 182656 bd904f0a63780777d49ed45a98c8c6bd C:\WINDOWS\system32\drivers\ndis.sys
01/25/2008 10:41 PM 36608 e8c07b7a56bb7ea82db4b5c8287ae528 C:\WINDOWS\system32\drivers\ip6fw.sys
02/12/2008 04:25 PM 2163712 a8b6c84ca67197bd45a78d985fe0419e C:\WINDOWS\system32\ntkrnlpa.exe
02/12/2008 04:10 PM 2285056 88df50b01155178fae28cf0f95572a2d C:\WINDOWS\system32\ntoskrnl.exe
02/03/2008 10:51 PM 1840128 f0d1a9d147e3722c4636fbb74a76723e C:\WINDOWS\explorer.exe
01/26/2008 05:57 AM 108544 c66f8642b4368436e1c5b6add83f5899 C:\WINDOWS\system32\services.exe
01/26/2008 05:57 AM 13312 e4b556449b263674e741bd10108498c8 C:\WINDOWS\system32\lsass.exe
01/26/2008 05:57 AM 15360 8324ed41ea4b936fab28e2bf101b7657 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [01/26/2008 05:57 AM 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [06/28/2008 01:12 PM 5674352]
"Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" [05/20/2008 05:27 PM 2474031]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="C:\Program Files\IDT\WDM\sttray.exe" [05/07/2008 02:12 PM 413696]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/28/2008 01:10 PM 185896]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [02/12/2008 10:06 AM 262401]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [03/25/2008 04:28 AM 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [01/26/2008 05:57 AM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [01/26/2008 05:57 AM 99840 C:\WINDOWS\system32\advpack.dll]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [10/23/2006 2:01:00 AM 734872]
PalTalk.lnk - C:\Program Files\Paltalk Messenger\paltalk.exe [5/9/2008 12:17:29 AM 10452992]
RocketDock.lnk - C:\Program Files\RocketDock\RocketDock.exe [6/28/2008 11:58:14 AM 495616]
«©م، ¢¬نïé Adobe Reader.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [10/23/2006 3:48:00 AM 40048]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
antiwpa.dll 07/23/2006 02:49 AM 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
R2 AntiVirMailService;Avira AntiVir Premium MailGuard;"C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe" [06/28/2008 01:16 PM]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;"C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE" [04/09/2008 03:57 PM]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;"C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe" [02/07/2008 10:06 AM]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [02/20/2008 09:19 PM]
*Newly Created Service* - CATCHME
*Newly Created Service* - OSE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [URL="http://www.gmer.net/"]http://www.gmer.net[/URL]
Rootkit scan 2008-06-28 18:09:31
Windows 5.1.2600 Service Pack 3, v.3300 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 06/28/2008 18:11:25
ComboFix-quarantined-files.txt 2008-06-28 16:10:37
Pre-Run: 45,551,050,752 bytes free
Post-Run: 45,803,192,320 bytes free
148 --- E O F --- 2008-06-28 13:24:15[/CENTER]