Hi broni,
As per your instructions, please find the following :
ComboFix 09-07-08.01 - Satish 07/08/2009 23:05.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.446.183 [GMT -7:00]
Running from: c:\documents and settings\Satish\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090708-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
D:\Autorun.inf
E:\Autorun.inf
F:\autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
((((((((((((((((((((((((( Files Created from 2009-06-09 to 2009-07-09 )))))))))))))))))))))))))))))))
.
2009-07-07 22:37 . 2009-07-08 15:22 -------- d-----w- c:\program files\a-squared Free
2009-07-07 21:28 . 2009-07-08 15:33 -------- d-----w- C:\Spyware Cleaner 2009
2009-07-07 20:50 . 2009-07-09 05:59 95744 ----a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\Updates\Condition.dll
2009-07-06 16:00 . 2009-07-06 16:00 -------- d-----w- c:\program files\ArzooSoft Solutions
2009-07-05 19:29 . 2009-07-05 19:29 12328 ----a-w- c:\documents and settings\Satish\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-02 22:19 . 2009-07-02 22:19 -------- d-----w- c:\windows\OPTIONS
2009-07-02 22:17 . 2009-07-09 06:09 -------- d-----w- c:\windows\system32\Lang
2009-07-02 22:13 . 2006-01-04 11:27 86016 ------r- c:\windows\SoundMan.exe
2009-07-02 22:13 . 2005-10-21 13:49 356352 ------r- c:\windows\RtlUpd.exe
2009-07-02 22:13 . 2006-01-06 16:39 9710592 ------r- c:\windows\RTLCPL.exe
2009-07-02 22:13 . 2006-01-13 17:13 4137984 ------r- c:\windows\system32\drivers\RtkHDAud.Sys
2009-07-02 22:13 . 2006-01-11 17:23 15961088 ------r- c:\windows\RTHDCPL.exe
2009-07-02 22:13 . 2006-01-09 14:32 2158592 ------r- c:\windows\MicCal.exe
2009-07-02 22:13 . 2009-07-02 22:13 -------- d-----w- c:\program files\Realtek
2009-07-02 22:13 . 2006-01-04 11:29 2809856 ------r- c:\windows\alcwzrd.exe
2009-07-02 22:13 . 2005-05-03 18:43 69632 ------r- c:\windows\Alcmtr.exe
2009-07-02 22:13 . 2005-04-16 22:20 487424 ------r- c:\windows\RtlExUpd.dll
2009-07-02 22:12 . 2009-07-02 22:12 -------- d-----w- c:\documents and settings\Satish\Local Settings\Application Data\ATI
2009-07-02 22:12 . 2009-07-02 22:12 -------- d-----w- c:\documents and settings\Satish\Application Data\ATI
2009-07-02 22:10 . 2009-07-02 22:10 -------- d-----w- c:\program files\ATI Technologies
2009-07-02 22:07 . 2006-01-26 15:57 520192 ------w- c:\windows\system32\ati2sgag.exe
2009-07-02 22:07 . 2006-01-15 22:04 307200 ----a-r- c:\windows\system32\atiiiexx.dll
2009-07-02 22:07 . 2005-12-08 17:01 112421 ----a-r- c:\windows\system32\atiicdxx.dat
2009-07-02 22:00 . 2009-07-02 22:19 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-02 22:00 . 2009-07-02 22:10 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-02 22:00 . 2009-07-02 22:00 -------- d-----w- c:\program files\MSXML 4.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-07-09 06:09 . 2009-07-02 11:04 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-06 19:33 . 2009-07-02 21:51 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-02 21:52 . 2009-07-02 21:52 -------- d-----w- c:\program files\microsoft frontpage
2009-07-02 21:48 . 2009-07-02 21:48 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-07-02 11:05 . 2009-07-02 11:03 -------- d-----w- c:\program files\DAP
2009-07-02 11:03 . 2009-07-02 11:03 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedBit
2009-07-02 11:03 . 2009-07-02 11:03 50688 ----a-w- c:\windows\system32\wbhelp2.dll
2009-07-02 10:20 . 2009-07-02 10:20 -------- d-----w- c:\program files\Alwil Software
2009-07-02 10:04 . 2009-07-02 10:04 0 ----a-w- c:\windows\nsreg.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2009-07-02 3061248]
"USB Threat Defender"="c:\program files\ArzooSoft Solutions\USB Threat Defender\utdefender.exe" [2009-06-22 1215488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp. exe" [2009-02-05 81000]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-01-11 15961088]
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [7/2/2009 3:20 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswF sBlk.sys [7/2/2009 3:20 AM 20560]
.
.
------- Supplementary Scan -------
.
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
FF - ProfilePath - c:\documents and settings\Satish\Application Data\Mozilla\Firefox\Profiles\p2xw49rb.default\
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-07-08 23:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(536)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\ati2evxx.exe
c:\program files\a-squared Free\a2service.exe
c:\windows\system32\wscntfy.exe
.
************************************************** ************************
.
Completion time: 2009-07-09 23:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-09 06:12
Pre-Run: 18,425,548,800 bytes free
Post-Run: 18,413,551,616 bytes free
113
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:16:12 PM, on 7/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\DAP\DAP.EXE
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Bing
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKCU\..\Run: [USB Threat Defender] C:\Program Files\ArzooSoft Solutions\USB Threat Defender\utdefender.exe /b
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
--
End of file - 2973 bytes
Adobe Flash Player 10 Plugin
a-squared Free 4.5
ATI Catalyst Control Center
ATI Display Driver
avast! Antivirus
Download Accelerator Plus (DAP)
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Microsoft .NET Framework 2.0
Mozilla Firefox (3.0.1)
MSXML 4.0 SP2 Parser and SDK
REALTEK Gigabit and Fast Ethernet NIC Driver
Realtek High Definition Audio Driver