ComboFix 08-08-28.06 - الصقر الجريح 08/31/2008 11:46:01.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.182 [GMT 3:00]
Running from: C:\Documents and Settings\الصقر الجريح\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\NetMeeting\readme.eml
C:\WINDOWS\system32\runouce.exe
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-31 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-31 08:02 --------- d-----w C:\Program Files\Sun
2008-08-31 08:02 --------- d-----w C:\Program Files\Java
2008-08-31 07:54 --------- d-----w C:\Program Files\Common Files\Java
2008-08-28 12:25 --------- d-----w C:\Program Files\iVocalize Web Conference 4
2008-08-28 09:32 --------- d-----w C:\Program Files\QuickTime
2008-08-28 08:23 720,896 ----a-w C:\WINDOWS\iun6002ev.exe
2008-08-28 08:23 --------- d-----w C:\Program Files\Quran Kareem
2008-08-26 08:52 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-08-26 08:18 --------- d-----w C:\Program Files\Google
2008-08-26 07:20 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-08-26 07:20 --------- d-----w C:\Program Files\VSO
2008-08-26 06:41 --------- d-----w C:\Program Files\DebugDiag
2008-08-24 12:56 --------- d-----w C:\Program Files\Ashampoo
2008-08-24 12:43 --------- d-----w C:\Program Files\Alcohol Soft
2008-08-24 12:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-08-24 12:29 --------- d-----w C:\Program Files\UltraISO
2008-08-24 12:29 --------- d-----w C:\Program Files\Common Files\EZB Systems
2008-08-24 12:10 --------- d-----w C:\Program Files\Lavasoft
2008-08-24 12:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\dtv
2008-08-24 12:03 --------- d-----w C:\Program Files\Windows Live
2008-08-24 12:01 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-24 11:56 --------- d-----w C:\Program Files\Real
2008-08-24 11:55 --------- d-----w C:\Program Files\Common Files\Real
2008-08-24 11:54 --------- d-----w C:\Program Files\Common Files\xing shared
2008-08-24 11:53 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-24 11:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-24 11:38 --------- d-----w C:\Program Files\Realtek
2008-08-24 11:38 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-24 11:27 --------- d-----w C:\Program Files\Intel
2008-08-24 08:36 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((( snapshot_Sun 08-31-2008_11.40.23.96 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-31 07:26:27 40,316 ----a-w C:\WINDOWS\system32\perfc001.dat
+ 2008-08-31 08:44:09 40,316 ----a-w C:\WINDOWS\system32\perfc001.dat
- 2008-08-31 07:26:27 40,326 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-08-31 08:44:09 40,326 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-31 07:26:27 251,946 ----a-w C:\WINDOWS\system32\perfh001.dat
+ 2008-08-31 08:44:09 251,946 ----a-w C:\WINDOWS\system32\perfh001.dat
- 2008-08-31 07:26:27 311,938 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-08-31 08:44:09 311,938 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [11/29/2007 07:25 PM 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [08/26/2008 11:18 AM 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [06/13/2006 04:57 AM 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [06/13/2006 04:57 AM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [06/13/2006 04:57 AM 118784]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [07/19/2006 04:41 AM 59900]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [08/24/2008 02:54 PM 180269]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM 46444]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM 144784]
"Runonce"="C:\WINDOWS\system32\runouce.exe" [08/31/2008 11:49 AM 10748]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 12:56 AM 110592 C:\WINDOWS\system32\bthprops.cpl]
"SkyTel"="SkyTel.EXE" [07/19/2006 04:42 AM 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [07/19/2006 04:42 AM 16248320 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.DIV3"= DIVXc32.dll
"vidc.DIV4"= DIVXc32f.dll
"msacm.divxa32"= DivXa32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R2 DbgSvc;Debug Diagnostic Service;C:\Program Files\DebugDiag\DbgSvc.exe [01/16/2007 10:10 AM]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O17 -: HKLM\CCS\Interface\{B400D5CE-2F48-4592-A285-993545630CD4}: NameServer = 213.165.32.134,213.165.32.137
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-31 11:49:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Runonce = C:\WINDOWS\system32\runouce.exe?^??????????????q???????????????????q????????????<???]???'??|2??w???wo??w????0u??????(??|???????????????????????????????|???|!???x???????(??|D???????????????????????????????????????????????????????????????????????????????Z?@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\msdtc.exe
C:\DOCUME~1\8DF3~1\LOCALS~1\temp\RtkBtMnt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Completion time: 08/31/2008 11:53:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-31 08:53:05
ComboFix2.txt 2008-08-31 08:40:44
ComboFix3.txt 2008-08-29 08:29:53
Pre-Run: 46,767,927,296 bytes free
Post-Run: 46,748,925,952 bytes free
141 --- E O F --- 2008-08-31 08:01:38