ComboFix 08-12-04.04 - maroma 12/05/2008 23:39:22.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1256.20.1033.18.94 [GMT 2:00]
Running from: c:\documents and settings\maroma\Desktop\ComboFix.exe
 * Created a new restore point

[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\maroma\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk
c:\documents and settings\maroma\Start Menu\Antivirus 2009
c:\documents and settings\maroma\Start Menu\Antivirus 2009\Antivirus 2009.lnk
c:\documents and settings\maroma\Start Menu\Antivirus 2009\Uninstall Antivirus 2009.lnk
c:\program files\Antivirus 2009
c:\program files\Antivirus 2009\av2009.exe
c:\program files\IEToolbar
c:\program files\IEToolbar\   \   copy.bmp
c:\program files\IEToolbar\   \abc.bmp
c:\program files\IEToolbar\   \basis.xml
c:\program files\IEToolbar\   \favicon.ico
c:\program files\IEToolbar\   \icons.bmp
c:\program files\IEToolbar\   \Icons_dorar.gif
c:\program files\IEToolbar\   \Icons_srch copy.bmp
c:\program files\IEToolbar\   \Icons_srch.gif
c:\program files\IEToolbar\   \ijl15.dll
c:\program files\IEToolbar\   \info.txt
c:\program files\IEToolbar\   \logo.bmp
c:\program files\IEToolbar\   \rs.bmp
c:\program files\IEToolbar\   \rtl.crc
c:\program files\IEToolbar\   \rtl.dll
c:\program files\IEToolbar\   \Shortcuts.cnf
c:\program files\IEToolbar\   \tbhelper.dll
c:\program files\IEToolbar\   \tell_a_friend.dll
c:\program files\IEToolbar\   \Thumbs.db
c:\program files\IEToolbar\   \uninstall.exe
c:\program files\IEToolbar\   \version.txt
c:\program files\IEToolbar\   \websave_plugin.dll
c:\program files\IEToolbar\   \your_logo.png
c:\windows\system32\explorer32.exe
c:\windows\system32\ieupdates.exe
c:\windows\system32\IJL15.dll
c:\windows\system32\ImgX5.dll
c:\windows\system32\scui.cpl
c:\windows\system32\uninstall.exe
c:\windows\system32\winsrc.dll

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SERVICEM
-------\Service_ServiceM


(((((((((((((((((((((((((   Files Created from 2008-11-05 to 2008-12-05  )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-05 21:43	---------	d-----w	c:\program files\microsoft frontpage
2008-12-05 21:42	---------	d-----w	c:\documents and settings\maroma\Application Data\Free Download Manager
2008-12-05 20:52	94,208	----a-w	c:\windows\system32\ScrUnZip.dll
2008-12-05 20:48	19,456	----a-w	c:\windows\system32\RemoveScr.exe
2008-12-05 20:48	10,338,764	----a-w	c:\windows\system32\Untitled.SCR
2008-12-05 20:48	---------	d-----w	c:\program files\Screensaver DIY TE
2008-12-05 16:38	---------	d-----w	c:\program files\Axialis
2008-12-05 14:07	424,960	----a-w	c:\windows\system32\_ISource21.dll
2008-12-05 13:42	8,296,490	----a-w	c:\windows\system32\Project1.scr
2008-12-05 13:35	---------	d-----w	c:\documents and settings\maroma\Application Data\Axialis
2008-12-05 13:29	---------	d-----w	c:\documents and settings\maroma\Application Data\Stardust
2008-12-05 13:08	---------	d-----w	c:\documents and settings\All Users\Application Data\SWiSHMax2WorkFolder
2008-12-05 12:20	---------	d-----w	c:\program files\Wisdom-soft AutoScreenRecorder 3 Pro
2008-12-04 17:32	---------	d-----w	c:\program files\Smilebox
2008-12-04 16:47	---------	d-----w	c:\documents and settings\maroma\Application Data\Nuotex
2008-11-29 19:25	---------	d-----w	c:\program files\Active Media Technology
2008-11-28 16:55	9,628,367	----a-w	c:\windows\system32\1.Scr
2008-11-25 17:45	---------	d-----w	c:\program files\Internet Download Manager
2008-11-22 21:20	---------	d-----w	c:\documents and settings\maroma\Application Data\DMCache
2008-11-22 18:12	---------	d-----w	c:\program files\TryMedia
2008-11-15 20:02	---------	d---a-w	c:\documents and settings\All Users\Application Data\TEMP
2008-11-15 18:52	4,316,499	----a-w	c:\windows\system32\ .Scr
2008-11-15 17:25	587,264	----a-w	c:\windows\system32\Enter your screen saver title here ! Screen Saver.scr
2008-11-15 17:19	149,504	----a-w	c:\windows\system32\Mpegdll.dll
2008-11-07 13:05	---------	d-----w	c:\documents and settings\maroma\Application Data\IDM
2008-11-01 19:41	---------	d-----w	c:\program files\Common Files\Adobe
2008-11-01 19:36	---------	d--h--w	c:\program files\InstallShield Installation Information
2008-11-01 18:02	---------	d-----w	c:\program files\ 
2008-11-01 16:02	---------	d-----w	c:\program files\Fadaeal
2008-11-01 15:56	---------	d-----w	c:\program files\Alazakar
2008-10-24 11:21	455,296	----a-w	c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:21	455,296	------w	c:\windows\system32\dllcache\mrxsmb.sys
2008-10-17 18:14	---------	d-----w	c:\program files\QuickWiz
2008-10-17 18:14	---------	d-----w	c:\program files\Common Files\GuruNet Shared
2008-10-17 18:14	---------	d-----w	c:\program files\Common Files\Accent Shared
2008-10-16 12:13	202,776	----a-w	c:\windows\system32\wuweb.dll
2008-10-16 12:13	1,809,944	----a-w	c:\windows\system32\wuaueng.dll
2008-10-16 12:12	561,688	----a-w	c:\windows\system32\wuapi.dll
2008-10-16 12:12	323,608	----a-w	c:\windows\system32\wucltui.dll
2008-10-16 12:09	92,696	----a-w	c:\windows\system32\cdm.dll
2008-10-16 12:09	51,224	----a-w	c:\windows\system32\wuauclt.exe
2008-10-16 12:09	43,544	----a-w	c:\windows\system32\wups2.dll
2008-10-16 12:08	34,328	----a-w	c:\windows\system32\wups.dll
2008-10-15 16:34	337,408	------w	c:\windows\system32\dllcache\netapi32.dll
2008-10-05 19:09	---------	d-----w	c:\program files\Free Download Manager
2008-10-05 14:19	---------	d-----w	c:\documents and settings\maroma\Application Data\Thinstall
2008-10-05 14:17	---------	d-----w	c:\program files\Acoustica MP3 Audio Mixer
2008-10-03 17:41	6,066,176	------w	c:\windows\system32\dllcache\ieframe.dll
2008-09-17 23:00	7,943,190	----a-w	c:\windows\  .scr
2008-09-17 23:00	230,306	----a-w	c:\windows\uninstall   .exe
2008-09-15 12:12	1,846,400	----a-w	c:\windows\system32\win32k.sys
2008-09-15 12:12	1,846,400	------w	c:\windows\system32\dllcache\win32k.sys
2008-09-10 01:14	1,307,648	----a-w	c:\windows\system32\msxml6.dll
2008-09-10 01:14	1,307,648	------w	c:\windows\system32\dllcache\msxml6.dll
2008-09-08 21:03	51,712	----a-w	c:\windows\system32\sirenacm.dll
2008-09-08 10:41	333,824	------w	c:\windows\system32\dllcache\srv.sys
2008-09-05 21:30	241,704	------w	c:\windows\system32\dllcache\wgaLogon.dll
2008-09-05 21:29	917,032	------w	c:\windows\system32\dllcache\WgaTray.exe
2008-09-05 12:56	287,744	----a-w	c:\windows\WLXPGSS.SCR
.

------- Sigcheck -------

02/03/2008 10:51 PM  1840128  f0d1a9d147e3722c4636fbb74a76723e	c:\windows\explorer.exe
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a418ee1a-8324-4cfa-8431-5aa3da61e43e}"= "c:\program files\rasoulallah4\tbraso.dll" [08/05/2008 02:13 AM 1610264]

[HKEY_CLASSES_ROOT\clsid\{a418ee1a-8324-4cfa-8431-5aa3da61e43e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a418ee1a-8324-4cfa-8431-5aa3da61e43e}]
08/05/2008 02:13 AM	1610264	--a------	c:\program files\rasoulallah4\tbraso.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a418ee1a-8324-4cfa-8431-5aa3da61e43e}"= "c:\program files\rasoulallah4\tbraso.dll" [08/05/2008 02:13 AM 1610264]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A418EE1A-8324-4CFA-8431-5AA3DA61E43E}"= "c:\program files\rasoulallah4\tbraso.dll" [08/05/2008 02:13 AM 1610264]

[HKEY_CLASSES_ROOT\clsid\{a418ee1a-8324-4cfa-8431-5aa3da61e43e}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [09/08/2008 11:02 PM 3513344]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [05/27/2008 08:58 PM 4269296]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [01/26/2008 05:57 AM 15360]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [05/20/2008 05:27 PM 2474031]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [01/01/2007 11:22 PM 3739648]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [01/26/2008 05:57 AM 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [08/26/2008 09:24 AM 124928 c:\windows\system32\advpack.dll]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RocketDock.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\RocketDock.lnk
backup=c:\windows\pss\RocketDock.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^maroma^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\maroma\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^maroma^Start Menu^Programs^Startup^Ela-Salaty.lnk]
path=c:\documents and settings\maroma\Start Menu\Programs\Startup\Ela-Salaty.lnk
backup=c:\windows\pss\Ela-Salaty.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 01/26/2008 05:57 AM 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Free Download Manager]
--a------ 05/20/2008 05:27 PM 2474031 c:\program files\Free Download Manager\fdm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 09/08/2008 11:02 PM 3513344 c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rscmpt]
-ra------ 08/24/2002 07:48 PM 481792 c:\windows\system32\Rscmpt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 08/27/2008 03:00 PM 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 05/27/2008 08:58 PM 4269296 c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\K-Lite Codec Pack\\Media Player Classic\\mplayerc.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

.
- - - - ORPHANS REMOVED - - - -

BHO-{52E17EE0-7BF3-43B4-954C-DCEEF4A4C724} - c:\program files\IEToolbar\   \rtl.dll
Toolbar-{89E551A3-C402-4F52-AD12-FD6D3BC69CC2} - c:\program files\IEToolbar\   \rtl.dll
WebBrowser-{89E551A3-C402-4F52-AD12-FD6D3BC69CC2} - c:\program files\IEToolbar\   \rtl.dll
MSConfigStartUp-40558573568536047362322869019000 - c:\program files\Antivirus 2009\av2009.exe
MSConfigStartUp-egui - c:\program files\Eset\ESET NOD32 Antivirus\egui.exe


.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Google Search - c:\program files\Google\googletoolbar.dll/cmsearch.html
IE: Backward &Links - c:\program files\Google\googletoolbar.dll/cmbacklinks.html
IE: Cac&hed Snapshot of Page - c:\program files\Google\googletoolbar.dll/cmcache.html
IE: Free Download Manager    - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Si&milar Pages - c:\program files\Google\googletoolbar.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\googletoolbar.dll/cmtrans.html
IE:      - file://c:\program files\Free Download Manager\dlselected.htm
IE:      - file://c:\program files\Free Download Manager\dlall.htm
IE:     - file://c:\program files\Free Download Manager\dllink.htm
IE: {89E551A3-C402-4F52-AD12-FD6D3BC69CC2} - {89E551A3-C402-4F52-AD12-FD6D3BC69CC2} - c:\program files\IEToolbar\   \rtl.dll

c:\windows\system32\msvcrt.dll - c:\windows\system32\mfc42.dll
c:\windows\system32\olepro32.dll
c:\windows\Downloaded Program Files\imcv1.dll
O16 -: {6924091F-CD97-41E1-B1D4-D9079409D413}
hxxp://208.43.121.114/IMSCP/talk.cab
c:\windows\Downloaded Program Files\talk.inf

c:\program files\LtUcx\1003\c0.dll - c:\windows\system32\msvcrt.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\olepro32.dll
c:\windows\Downloaded Program Files\Authenticatedll.dll
O16 -: {8C159DFD-DC9C-4077-B3B6-114A8D64B6D2}
hxxp://74.53.69.86/cp/files/talk3.cab
c:\windows\Downloaded Program Files\talk.inf
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-05 23:43:59
Windows 5.1.2600 Service Pack 3, v.5657 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(468)
c:\windows\system32\SAMLIB.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\wscntfy.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 12/05/2008 23:46:34 - machine was rebooted
ComboFix-quarantined-files.txt  2008-12-05 21:46:29

Pre-Run: 5,486,010,368 bytes free
Post-Run: 5,718,310,912 bytes free

244	--- E O F ---	2008-11-15 13:12:25
