ComboFix 08-06-30.2 - it 07/02/2008 9:57:23.1 - NTFSx86
Running from: C:\Documents and Settings\it\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\WINDOWS\artools.dll
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-02 to 2008-07-02 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-02 06:56 --------- d-----w C:\Documents and Settings\it\Application Data\DMCache
2008-07-02 04:52 --------- d-----w C:\Program Files\MPlayer for Windows
2008-07-02 02:29 --------- d-----w C:\Program Files\TechSmith
2008-07-02 02:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\TechSmith
2008-07-02 02:15 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-02 00:53 --------- d-----w C:\Program Files\Common Files\delet
2008-07-01 04:20 --------- d-----w C:\Program Files\Java
2008-06-29 15:43 --------- d-----w C:\Program Files\Real_SC
2008-06-29 15:23 --------- d-----w C:\Documents and Settings\it\Application Data\Ashampoo
2008-06-28 08:24 --------- d-----w C:\Program Files\Paltalk Messenger
2008-06-27 23:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-06-27 22:19 --------- d-----w C:\Program Files\Common Files\TechSmith Shared
2008-06-27 21:31 --------- d-----w C:\Program Files\Ela-Salaty
2008-06-27 05:34 --------- d-----w C:\Program Files\Microsoft Works
2008-06-27 04:42 --------- d-----w C:\Program Files\Project1
2008-06-27 04:35 --------- d-----w C:\Program Files\Hotspot_Shield
2008-06-27 04:35 --------- d-----w C:\Program Files\Google
2008-06-27 04:35 --------- d-----w C:\Program Files\Conduit
2008-06-25 06:11 --------- d-----w C:\Documents and Settings\it\Application Data\Pegtop
2008-06-25 05:59 --------- d-----w C:\Program Files\Hotspot Shield
2008-06-25 04:33 --------- d-----w C:\Program Files\Windows Updates Downloader
2008-06-24 22:05 286,720 ------w C:\WINDOWS\Setup1.exe
2008-06-24 22:04 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-06-23 17:30 --------- d-----w C:\Program Files\Easy GIF Animator
2008-06-23 03:19 153,600 ----a-w C:\WINDOWS\system32\TLBINF32.DLL
2008-06-21 22:20 --------- d-----w C:\Program Files\Common Files\xing shared
2008-06-21 22:20 --------- d-----w C:\Program Files\Common Files\Real
2008-06-21 22:08 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-06-21 21:14 --------- d-----w C:\Program Files\FTPRush
2008-06-21 19:11 --------- d-----w C:\Documents and Settings\it\Application Data\TuneUp Software
2008-06-21 17:58 --------- d-----w C:\Documents and Settings\it\Application Data\FTPRush
2008-06-21 11:58 69,632 ----a-w C:\WINDOWS\uinst001.exe
2008-06-21 10:44 --------- d-----w C:\Documents and Settings\it\Application Data\Creative
2008-06-21 10:35 --------- d-----w C:\Program Files\PROnetworks
2008-06-21 10:13 --------- d-----w C:\Program Files\MSN Messenger
2008-06-21 10:12 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-06-21 10:12 --------- d-----w C:\Program Files\Windows Live
2008-06-21 10:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-21 09:48 --------- d-----w C:\Program Files\MSXML 6.0
2008-06-21 09:40 --------- d-----w C:\Program Files\MSBuild
2008-06-21 09:36 --------- d-----w C:\Program Files\Reference Assemblies
2008-06-21 08:05 --------- d-----w C:\Program Files\Internet Download Manager
2008-06-21 07:58 --------- d-----w C:\Program Files\SEO Studio
2008-06-21 07:57 --------- d-----w C:\Program Files\Real
2008-06-21 05:40 --------- d-----w C:\Documents and Settings\it\Application Data\Paltalk
2008-06-20 00:11 --------- d-----w C:\Documents and Settings\it\Application Data\32Find
2008-06-19 23:57 --------- d-----w C:\Program Files\Common Files\PCCamera
2008-06-19 23:57 --------- d-----w C:\Program Files\Circle Developement
2008-06-19 23:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Long slow road itch
2008-06-19 07:50 --------- d-----w C:\Documents and Settings\it\Application Data\IDM
2008-06-19 07:43 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-19 07:01 --------- d-----w C:\Documents and Settings\it\Application Data\Media Player Classic
2008-06-19 06:44 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-19 06:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-19 06:39 155,995 ----a-w C:\WINDOWS\java\Packages\FRLRVHN5.ZIP
2008-06-19 06:32 --------- d-----w C:\Program Files\VideoCAM GE111
2008-06-19 06:31 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-19 01:37 --------- d-----w C:\Program Files\Creative
2008-06-19 01:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Creative
2008-06-19 00:55 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-06-19 00:55 --------- d-----w C:\Program Files\Common Files\L&H
2008-06-19 00:50 --------- d-----w C:\Program Files\32Find
2008-06-19 00:49 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-06-19 00:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-06-18 23:29 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-06-18 23:24 4,096 --sh--r C:\WINDOWS\system32\runouce.exe
2008-06-18 23:23 --------- d-----w C:\Program Files\Common Files\Java
2008-06-18 23:13 --------- d-----w C:\Program Files\microsoft frontpage
2008-06-14 17:59 271,616 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:14 1,285,632 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [06/19/2008 09:48 AM 939516]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Runonce"="C:\WINDOWS\system32\runouce.exe" [06/19/2008 02:24 AM 4096]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/22/2008 01:20 AM 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [03/25/2008 04:28 AM 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
08/12/2005 05:25 AM 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.YV12"= yv12vfw.dll
"msacm.ac3filter"= ac3filter.acm
"msacm.divxa32"= divxa32.acm
"msacm.ctmp3"= C:\WINDOWS\system32\ctmp3.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
path=C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalTalk.lnk
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^it^قائمة ابدأ^البرامج^بدء التشغيل^Ela-Salaty.lnk]
path=C:\Documents and Settings\it\قائمة ابدأ\البرامج\بدء التشغيل\Ela-Salaty.lnk
backup=C:\WINDOWS\pss\Ela-Salaty.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 06/19/2008 09:48 AM 939516 C:\Program Files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"G:\\Programs\\LeapFTP\\LeapFTP.exe"=
*Newly Created Service* - CATCHME
*Newly Created Service* - HTTPFILTER
.
s of the 'Scheduled Tasks' folder
"2008-07-02 01:00:00 C:\WINDOWS\Tasks\ACB850F391C7C287.job"
- c:\docume~1\it\applic~1\32find\proxy loud film.exe
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
MSConfigStartUp-Super Screen Capture - C:\DOCUME~1\it\LOCALS~1\Temp\RarSFX0\Super Screen Capture\SSCapture.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-02 09:58:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Runonce = C:\WINDOWS\system32\runouce.exe?^??????????????q???????????????????q????????????<???]???'??|???w???w???w????0u?????????|???????????????????????????????|,??|!???x??????????|D???????????????????????????????????????????????????????????????????????????????Z?C
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 07/02/2008 9:59:32
ComboFix-quarantined-files.txt 2008-07-02 06:59:27
Pre-Run: 69,970,890,752 bytes free
Post-Run: 69,992,554,496 bytes free
160 --- E O F --- 2008-06-28 00:01:10