This is ComboFix Log :ComboFix 07-06-13.3 - D:\Documents and Settings\Ahmad\My Documents\My Completed Downloads\ComboFix.exe
"Ahmad" - 2007-06-15 3:16:57 - Service Pack 2
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
D:\WINDOWS\system32\nnetpeku.dll
D:\WINDOWS\system32\ukeptenn.ini
D:\WINDOWS\system32\qtstv.ini
D:\WINDOWS\system32\qtstv.tmp
D:\WINDOWS\system32\qtstv.bak1
D:\WINDOWS\system32\qtstv.bak2
D:\WINDOWS\system32\qtstv.ini2
D:\WINDOWS\system32\fhhkj.ini
D:\WINDOWS\system32\fhhkj.tmp
D:\WINDOWS\system32\fhhkj.bak1
D:\WINDOWS\system32\fhhkj.ini2
D:\WINDOWS\system32\fhhkj.bak2
D:\WINDOWS\system32\qtstv.ini
D:\WINDOWS\system32\qtstv.tmp
D:\WINDOWS\system32\qtstv.bak1
D:\WINDOWS\system32\qtstv.bak2
D:\WINDOWS\system32\qtstv.ini2
D:\WINDOWS\system32\fhhkj.ini
D:\WINDOWS\system32\fhhkj.tmp
D:\WINDOWS\system32\fhhkj.bak1
D:\WINDOWS\system32\fhhkj.ini2
D:\WINDOWS\system32\fhhkj.bak2
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((( Files Created from 2007-05-15 to 2007-06-15 )))))))))))))))))))))))))))))))
2007-06-15 03:16 49,152 --a------ D:\WINDOWS\nircmd.exe
2007-06-13 10:13 <DIR> d-------- D:\Program Files\CCleaner
2007-06-12 00:11 26,752 -ra------ D:\WINDOWS\system32\drivers\ShldDrv.sys
2007-06-12 00:11 163,856 -ra------ D:\WINDOWS\system32\drivers\PavProc.sys
2007-06-10 10:33 9,488 --a------ D:\WINDOWS\system32\sporder.dll
2007-06-10 10:33 158,200 --a------ D:\WINDOWS\system32\drivers\APPFCONT.DAT
2007-06-10 10:33 <DIR> d-------- D:\Program Files\Panda Software
2007-06-10 10:26 <DIR> d-------- D:\Program Files\XoftSpy
2007-06-09 11:49 <DIR> d-------- D:\Program Files\Adware & Spyware Firewall
2007-06-08 22:59 225,508 --a------ D:\WINDOWS\system32\mljji.dll
2007-05-28 02:13 <DIR> d-------- D:\Program Files\Pokemon PC 2.0
2007-05-26 14:26 <DIR> d-------- D:\Program Files\BitComet
2007-05-26 13:01 <DIR> d-------- D:\Program Files\uTorrent
2007-05-26 13:01 <DIR> d-------- D:\DOCUME~1\Ahmad\APPLIC~1\uTorrent
2007-05-26 12:04 <DIR> d-------- D:\Program Files\ooVoo
2007-05-26 12:04 <DIR> d-------- D:\DOCUME~1\Ahmad\APPLIC~1\InstallShield
2007-05-25 23:55 <DIR> d--hs---- D:\FOUND.002
2007-05-25 22:41 <DIR> d-------- D:\Program Files\Speed Gear 5
2007-05-22 01:34 <DIR> d-------- D:\Program Files\Billionaire
2007-05-16 22:58 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-14 12:42:22 -------- d-----w D:\Program Files\BrainWave Generator
2007-05-12 13:59:02 -------- d-----w D:\Program Files\STB Wizard
2007-05-02 12:44:48 -------- d-----w D:\Program Files\Reallusion
2007-05-02 12:43:26 -------- d-----w D:\Program Files\ORITE
2007-04-28 12:45:10 -------- d-----w D:\Program Files\FollowMe
2007-04-28 12:39:24 -------- d-----w D:\Program Files\Ace Translator
2007-04-28 12:33:30 -------- d-----w D:\Program Files\Pwndsoft
2007-04-22 12:27:14 -------- d-----w D:\DOCUME~1\Ahmad\APPLIC~1\Weather Studio
2007-04-21 01:07:58 -------- d-----w D:\DOCUME~1\Ahmad\APPLIC~1\Nokia Multimedia Player
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LanzarP2006"="D:\DOCUME~1\Ahmad\LOCALS~1\Temp\{46F920BB-78D1-4E27-B654-333E4BBEE00B}\{EEBA9416-3207-47E0-9022-116440599DBC}\..\..\P2006tmp\Install.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-10 12:00]
"Yahoo! Pager"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-27 15:22]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"PcSync"=D:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=D:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=D:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{240E2B94-741E-4513-B66A-60EC26A9EF26}"="%SystemRoot%\system32\ieframe.dll" []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders , digest.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3e233666-9b4d-11db-bc24-d5075ae14b08}]
AutoRun\command- D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
Open(&0)\command- Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8d5b221e-e505-11db-bcad-b6621f667dbc}]
AutoRun\command- D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
Open(&0)\command- Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ab5d3cc0-87e0-11db-bbf7-b48621f624bd}]
AutoRun\command- D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
Open(&0)\command- H:\Recycled\ctfmon.exe
Contents of the 'Scheduled Tasks' folder
2007-06-10 08:31:18 D:\WINDOWS\tasks\XoftSpy.job
2007-06-15 01:19:48 D:\WINDOWS\tasks\XoftSpySE 2.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-06-15 03:20:00
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-15 3:22:31 - machine was rebooted
D:\ComboFix-quarantined-files.txt ... 2007-06-15 03:21
--- E O F ---
--------------------------------------------------------------------------------------------------------
and This is Hijack :Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 3:35:32 AM, on 6/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\SYSTEM32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\eHome\ehRecvr.exe
D:\WINDOWS\eHome\ehSched.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\dllhost.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\system32\NOTEPAD.EXE
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Documents and Settings\Ahmad\My Documents\My Completed Downloads\HiJackThis_v2.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.net.sy:3128
O4 - HKLM\..\Run: [LanzarP2006] "D:\DOCUME~1\Ahmad\LOCALS~1\Temp\{46F920BB-78D1-4E27-B654-333E4BBEE00B}\{EEBA9416-3207-47E0-9022-116440599DBC}\..\..\P2006tmp\Install.exe" /SETUP:"/l0x0009"
<<< is This Normal? O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O17 - HKLM\System\CCS\Services\Tcpip\..\{80FBFB18-0E9E-4B17-8118-E7C00E6C0731}: NameServer = 192.168.2.14 192.168.2.9
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: IE Browseui preloader - {240E2B94-741E-4513-B66A-60EC26A9EF26} - D:\WINDOWS\system32\ieframe.dll
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - D:\WINDOWS\system32\ieframe.dll
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: kavsvc - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - D:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - D:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 2914 bytes