I still cannot find C:\WINDOWS\system32\AngAntiVirus.vbs, I checked even the hidden files. The combofix log is as follows.
ComboFix 08-06-15.1 - Abbas 2008-06-16 8:42:00.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.367 [GMT 4:00]
Running from: C:\Documents and Settings\Abbas\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\cfx32.ocx
C:\WINDOWS\system32\x64
E:\copy.exe
E:\host.exe
F:\copy.exe
F:\host.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-16 to 2008-06-16 )))))))))))))))))))))))))))))))
.
2008-06-15 16:20 . 2008-06-15 16:20 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-15 16:20 . 2008-06-15 16:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-15 16:20 . 2008-06-15 16:20 <DIR> d-------- C:\Documents and Settings\Abbas\Application Data\Malwarebytes
2008-06-15 16:20 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-15 16:20 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-15 16:19 . 2008-06-15 16:19 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-06-13 13:29 . 2008-06-13 13:29 <DIR> d-------- C:\Deckard
2008-06-13 09:48 . 2008-06-13 09:48 38,712 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-06-13 09:47 . 2008-06-13 09:47 <DIR> d-------- C:\Documents and Settings\Abbas\Application Data\Apple Computer
2008-06-13 09:46 . 2008-06-13 09:47 <DIR> d-------- C:\Program Files\Safari
2008-06-13 09:46 . 2008-06-13 09:46 <DIR> d-------- C:\Program Files\Apple Software Update
2008-06-13 09:46 . 2008-06-13 09:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-06-13 09:35 . 2008-06-15 17:20 <DIR> d-------- C:\Program Files\Hijack
2008-06-11 23:47 . 2008-04-14 15:01 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 23:47 . 2008-04-14 15:01 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 16:08 . 2008-06-11 16:08 <DIR> d-------- C:\Documents and Settings\Abbas\Application Data\Oxford
2008-06-11 16:07 . 2008-06-11 16:27 13 --a------ C:\WINDOWS\TEXTware.ini
2008-06-09 13:17 . 2008-06-09 13:17 <DIR> d-------- C:\Program Files\Oxford
2008-06-08 10:38 . 2008-06-08 10:39 <DIR> d-------- C:\Program Files\FOX Video Converter
2008-06-08 10:38 . 2004-05-26 21:37 719,872 --a------ C:\WINDOWS\system32\devil.dll
2008-06-08 10:38 . 2003-03-19 11:03 544,768 --a------ C:\WINDOWS\system32\msvcr71d.dll
2008-06-08 10:38 . 2002-01-05 14:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-06-08 10:38 . 2006-09-16 19:44 314,368 --a------ C:\WINDOWS\system32\avisynth.dll
2008-06-08 10:21 . 2008-06-08 10:22 <DIR> d-------- C:\Program Files\Video Editor
2008-06-08 08:53 . 2008-06-08 08:53 0 --a------ C:\WINDOWS\SMMVSplitter.INI
2008-06-08 08:52 . 2008-06-08 10:29 <DIR> d-------- C:\Program Files\Common Files\Elecard
2008-06-07 01:47 . 2008-06-07 01:48 <DIR> d-------- C:\Program Files\QuickTime
2008-06-07 01:47 . 2008-06-07 01:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-06 10:31 . 2008-06-06 10:31 <DIR> d-------- C:\Program Files\Hotspot Shield
2008-06-05 17:01 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-06-03 14:00 . 2008-06-03 14:00 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-06-03 13:59 . 2008-06-03 13:59 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-06-03 13:59 . 2008-06-03 13:59 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-06-03 13:43 . 2008-06-03 13:43 <DIR> d-------- C:\Program Files\AC3Filter
2008-06-03 13:43 . 2007-08-18 11:54 380,928 --a------ C:\WINDOWS\system32\ac3filter.acm
2008-06-01 10:44 . 2008-06-01 10:44 8,502 -rahs---- C:\WINDOWS\system32\AngAntiVirus.vbs
2008-05-31 13:03 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-05-31 13:03 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-05-31 13:03 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-05-31 13:03 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-05-30 19:09 . 2008-05-30 19:09 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-05-29 12:00 . 2008-05-29 12:00 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-05-29 12:00 . 2003-09-15 11:15 137,824 --a------ C:\WINDOWS\system32\drivers\aksifdh.sys
2008-05-29 12:00 . 2003-09-15 11:15 62,456 --a------ C:\WINDOWS\system32\drivers\AksUp.sys
2008-05-29 11:59 . 2008-06-16 08:25 <DIR> d-------- C:\Program Files\SourceNDP
2008-05-29 11:59 . 2008-05-29 12:00 <DIR> d-------- C:\Program Files\Common Files\Unisys
2008-05-29 11:59 . 2001-05-10 00:01 729,088 --a------ C:\WINDOWS\system32\_ISource21.dll
2008-05-29 11:59 . 2001-11-09 09:37 172,032 --a------ C:\WINDOWS\system32\psImage.ocx
2008-05-28 20:10 . 2008-05-28 20:10 <DIR> d-------- C:\Documents and Settings\Abbas\Application Data\Talkback
2008-05-28 20:10 . 2008-05-28 20:10 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-26 23:51 . 2008-05-26 23:52 <DIR> d-------- C:\Program Files\Trickshot
2008-05-24 13:12 . 2008-06-07 02:09 <DIR> d-------- C:\Documents and Settings\Abbas\Application Data\LimeWire
2008-05-21 16:55 . 2008-06-14 22:26 <DIR> d-------- C:\_Souq_
2008-05-21 09:16 . 2008-05-21 09:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-21 08:54 . 2007-02-20 16:04 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
2008-05-21 08:54 . 2007-02-20 16:04 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
2008-05-21 08:46 . 2008-05-21 08:46 <DIR> d-------- C:\Program Files\Bonjour
2008-05-21 08:40 . 2008-05-21 08:40 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-05-21 00:32 . 2008-05-21 00:32 <DIR> d--h----- C:\WINDOWS\PIF
2008-05-20 23:47 . 2008-05-20 23:47 <DIR> d-------- C:\Documents and Settings\Abbas\Application Data\Windows Desktop Search
2008-05-20 23:43 . 2008-05-20 23:43 <DIR> d-------- C:\Program Files\Windows Desktop Search
2008-05-20 23:21 . 2008-05-21 03:17 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-05-20 23:21 . 2008-05-21 08:57 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-05-20 18:18 . 2008-05-20 18:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-05-20 18:18 . 2008-06-16 07:56 <DIR> d-------- C:\Documents and Settings\Abbas\Application Data\Azureus
2008-05-20 18:14 . 2008-05-20 18:14 <DIR> d-------- C:\Program Files\CONEXANT
2008-05-20 17:58 . 2008-05-20 17:58 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\TeamViewer
2008-05-20 17:08 . 2008-05-20 17:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-05-20 17:02 . 2008-05-27 22:21 <DIR> d-------- C:\Documents and Settings\Abbas\Application Data\DivX
2008-05-20 17:02 . 2004-08-03 23:37 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-05-20 16:59 . 2008-05-20 18:37 <DIR> d-------- C:\Program Files\Azureus
2008-05-20 16:57 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-20 16:56 . 2008-05-20 16:57 <DIR> d-------- C:\Program Files\Java
2008-05-20 16:49 . 2008-05-20 16:49 <DIR> d-------- C:\Program Files\IrfanView
2008-05-20 16:45 . 2008-05-20 16:45 <DIR> d-------- C:\Program Files\Yahoo!
2008-05-20 16:41 . 2008-05-20 16:41 <DIR> d-------- C:\Program Files\Common Files\Java
2008-05-20 16:40 . 2008-04-23 08:16 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-05-20 16:40 . 2007-04-17 13:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-05-20 16:40 . 2007-03-08 09:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-05-20 16:40 . 2008-04-23 08:16 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-05-20 16:40 . 2008-04-23 08:16 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-05-20 16:40 . 2008-04-23 08:16 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-05-20 16:40 . 2008-04-23 08:16 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-05-20 16:40 . 2008-04-23 08:16 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-05-20 16:40 . 2008-04-22 11:39 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-05-20 16:39 . 2008-05-20 16:57 <DIR> d-------- C:\Program Files\LimeWire
2008-05-20 16:36 . 2008-05-20 16:36 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\TeamViewer
2008-05-20 16:36 . 2008-06-13 22:50 <DIR> d-------- C:\Program Files\TeamViewer3
2008-05-20 16:36 . 2008-05-27 13:59 <DIR> d-------- C:\Documents and Settings\Abbas\Application Data\TeamViewer
2008-05-20 16:35 . 2008-05-20 16:35 <DIR> d-------- C:\Documents and Settings\Abbas\temp
2008-05-20 16:24 . 2008-05-20 16:24 <DIR> d-------- C:\Program Files\Google
2008-05-20 16:23 . 2008-05-20 16:23 <DIR> d-------- C:\Program Files\GPLGS
2008-05-20 16:18 . 2008-05-20 16:18 <DIR> d-------- C:\Program Files\DivX
2008-05-20 16:18 . 2008-05-20 16:18 <DIR> d-------- C:\Program Files\Acro Software
2008-05-20 16:13 . 2008-05-20 16:13 <DIR> d-------- C:\Program Files\Microsoft Works
2008-05-20 16:09 . 2008-05-20 16:10 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-05-20 16:08 . 2008-05-20 16:08 <DIR> dr-h----- C:\MSOCache
2008-05-20 16:08 . 2008-05-26 08:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-20 16:08 . 2006-03-17 04:38 28,672 --------- C:\WINDOWS\system32\verclsid.exe
2008-05-20 16:02 . 2008-05-21 23:53 <DIR> d-------- C:\Program Files\Avast4
2008-05-20 16:01 . 2006-06-14 12:47 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2008-05-20 16:00 . 2008-05-20 16:00 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-05-20 16:00 . 2008-05-20 16:00 <DIR> d-------- C:\Program Files\Analog Devices
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-20 12:00 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-20 11:59 --------- d-----w C:\Program Files\Synaptics
2008-05-20 11:56 --------- d-----w C:\Program Files\Lenovo
2008-05-20 11:40 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
.
CODE
<pre>
----a-w 246,864 2007-02-21 14:41:06 C:\_Souq_\Products\Ebooks\Temp\82 New Ebooks With Resale\Atkins\Optimal Nutrition Versus Atkins Diet .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:37 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2007-04-25 00:41 110592]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-25 00:41 512000]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-04-25 00:41 925696]
"avast!"="C:\PROGRA~1\Avast4\ashDisp.exe" [2008-05-16 03:19 79224]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-08-09 16:32 135168]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-08-09 16:32 155648]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-08-09 16:32 131072]
"CertStoreInit"="C:\WINDOWS\system32\CertStoreInit" [ ]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 15:39 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
--a------ 2007-01-02 01:22 3739648 C:\Program Files\Google\Google Talk\googletalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 20:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-12-14 03:42 144784 C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 03:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 03:16]
R2 TeamViewer;TeamViewer 3;"C:\Program Files\TeamViewer3\TeamViewer_Host.exe" -service []
R2 Unisys_CAPI_TSManager;Unisys Source NDP Manager Service;C:\Program files\SourceNDP\bin\SourceNDPManager.exe [2007-03-06 07:56]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2008-01-24 01:25]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d7b91ebd-2ae5-11dd-9fc0-0018deb00d10}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe AngAntiVirus.vbs
*Newly Created Service* - CATCHME
*Newly Created Service* - DMADMIN
*Newly Created Service* - DMSERVER
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-16 08:46:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-16 8:47:06
ComboFix-quarantined-files.txt 2008-06-16 04:46:46
Pre-Run: 9,216,483,328 bytes free
Post-Run: 9,909,202,944 bytes free
212 --- E O F --- 2008-06-12 06:58:49