ComboFix 08-10-30.04 - vip 2008-10-30 14:20:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.503 [GMT 3:00]
Running from: C:\Documents and Settings\vip\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-30 )))))))))))))))))))))))))))))))
.
2008-10-30 13:30 . 2008-10-30 13:30 <DIR> d-------- C:\Program Files\Sun
2008-10-30 13:29 . 2008-10-30 13:29 <DIR> d-------- C:\Program Files\Java
2008-10-30 13:29 . 2008-10-30 13:29 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-10-30 13:29 . 2008-10-30 13:29 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-10-30 02:43 . 2008-10-30 02:43 <DIR> d-------- C:\VundoFix Backups
2008-10-28 20:09 . 2008-10-28 20:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\U3
2008-10-28 20:03 . 2008-10-28 21:34 <DIR> d-------- C:\Documents and Settings\vip\Application Data\U3
2008-10-28 09:55 . 2008-10-28 09:55 <DIR> d-------- C:\Documents and Settings\vip\Application Data\Ahead
2008-10-28 09:54 . 2008-10-28 09:54 <DIR> d-------- C:\Program Files\Nero
2008-10-28 09:54 . 2008-10-28 13:20 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-10-28 02:25 . 2008-10-28 02:25 <DIR> d-------- C:\Documents and Settings\vip\Application Data\Thinstall
2008-10-28 01:50 . 2008-10-28 01:50 <DIR> d-------- C:\Documents and Settings\vip\Application Data\URSoft
2008-10-28 01:50 . 2008-10-28 01:54 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-27 16:39 . 2008-06-14 20:31 271,616 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-10-27 16:39 . 2008-06-14 20:31 271,616 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-10-27 16:35 . 2008-08-14 16:20 2,190,720 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-27 16:35 . 2008-08-14 16:20 2,146,816 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-27 16:35 . 2008-08-14 16:20 2,067,584 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-27 16:35 . 2008-08-14 16:20 2,025,472 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-27 15:06 . 2008-10-27 15:06 98 --a------ C:\WINDOWS\WirelessFTP.INI
2008-10-27 14:38 . 2008-10-27 14:38 <DIR> d-------- C:\Program Files\Real
2008-10-27 14:38 . 2008-10-27 14:38 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-10-27 14:38 . 2008-10-27 14:38 <DIR> d-------- C:\Program Files\Common Files\Real
2008-10-27 04:06 . 2008-10-27 04:06 0 --a------ C:\WINDOWS\tosOBEX.INI
2008-10-26 23:39 . 2008-10-26 23:39 <DIR> d-------- C:\Program Files\Toshiba
2008-10-26 23:39 . 2007-04-24 13:20 113,920 --a------ C:\WINDOWS\system32\drivers\tosrfbd.sys
2008-10-26 23:39 . 2007-03-01 16:53 73,728 --a------ C:\WINDOWS\system32\drivers\Tosrfhid.sys
2008-10-26 23:39 . 2007-05-24 14:27 64,000 --a------ C:\WINDOWS\system32\drivers\tosrfcom.sys
2008-10-26 23:39 . 2007-01-22 10:43 53,376 --a------ C:\WINDOWS\system32\drivers\TosRfSnd.sys
2008-10-26 23:39 . 2006-10-10 19:33 41,600 --a------ C:\WINDOWS\system32\drivers\tosporte.sys
2008-10-26 23:39 . 2006-11-20 17:55 36,480 --a------ C:\WINDOWS\system32\drivers\tosrfbnp.sys
2008-10-26 23:39 . 2005-01-06 13:42 18,612 --a------ C:\WINDOWS\system32\drivers\tosrfnds.sys
2008-10-26 23:02 . 2008-10-26 23:04 5,405 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-10-26 22:40 . 2008-10-28 21:42 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-10-26 22:27 . 2008-10-26 22:27 <DIR> d-------- C:\Program Files\Alwil Software
2008-10-26 22:27 . 2003-03-19 00:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-10-26 22:27 . 2003-03-18 23:14 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll
2008-10-26 22:27 . 2003-02-21 07:42 348,160 --a------ C:\WINDOWS\system32\MSVCR71.dll
2008-10-26 12:26 . 2008-10-26 12:26 268 --ah----- C:\sqmdata19.sqm
2008-10-26 12:26 . 2008-10-26 12:26 244 --ah----- C:\sqmnoopt19.sqm
2008-10-26 12:09 . 2008-10-27 20:42 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-10-26 12:09 . 2005-02-25 06:34 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-10-26 12:03 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-10-26 12:03 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-10-26 12:03 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-10-26 12:03 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-10-26 12:03 . 2007-07-30 19:21 19,288 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-10-26 08:20 . 2008-10-26 08:20 268 --ah----- C:\sqmdata18.sqm
2008-10-26 08:20 . 2008-10-26 08:20 244 --ah----- C:\sqmnoopt18.sqm
2008-10-26 08:13 . 2008-10-26 08:13 268 --ah----- C:\sqmdata17.sqm
2008-10-26 08:13 . 2008-10-26 08:13 244 --ah----- C:\sqmnoopt17.sqm
2008-10-26 06:53 . 2008-10-26 06:53 268 --ah----- C:\sqmdata16.sqm
2008-10-26 06:53 . 2008-10-26 06:53 244 --ah----- C:\sqmnoopt16.sqm
2008-10-26 06:50 . 2008-10-26 06:50 268 --ah----- C:\sqmdata15.sqm
2008-10-26 06:50 . 2008-10-26 06:50 244 --ah----- C:\sqmnoopt15.sqm
2008-10-26 06:42 . 2008-10-26 06:42 268 --ah----- C:\sqmdata14.sqm
2008-10-26 06:42 . 2008-10-26 06:42 244 --ah----- C:\sqmnoopt14.sqm
2008-10-26 03:51 . 2008-10-26 03:51 268 --ah----- C:\sqmdata13.sqm
2008-10-26 03:51 . 2008-10-26 03:51 244 --ah----- C:\sqmnoopt13.sqm
2008-10-26 02:57 . 2008-10-26 02:57 <DIR> d-------- C:\Program Files\TechSmith
2008-10-26 02:57 . 2008-10-26 02:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TechSmith
2008-10-26 02:52 . 2008-10-26 02:52 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-26 01:44 . 2008-10-26 01:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2008-10-26 00:48 . 2008-10-26 00:58 <DIR> d-------- C:\Program Files\Internet Download Manager
2008-10-26 00:48 . 2008-10-30 02:39 <DIR> d-------- C:\Documents and Settings\vip\Application Data\IDM
2008-10-26 00:48 . 2008-10-30 14:22 <DIR> d-------- C:\Documents and Settings\vip\Application Data\DMCache
2008-10-26 00:40 . 2008-10-26 21:21 <DIR> d-------- C:\Documents and Settings\vip\Contacts
2008-10-25 15:25 . 2008-10-25 15:25 268 --ah----- C:\sqmdata12.sqm
2008-10-25 15:25 . 2008-10-25 15:25 244 --ah----- C:\sqmnoopt12.sqm
2008-10-25 15:13 . 2008-10-25 15:13 268 --ah----- C:\sqmdata11.sqm
2008-10-25 15:13 . 2008-10-25 15:13 244 --ah----- C:\sqmnoopt11.sqm
2008-10-25 03:39 . 2008-10-25 03:39 268 --ah----- C:\sqmdata10.sqm
2008-10-25 03:39 . 2008-10-25 03:39 244 --ah----- C:\sqmnoopt10.sqm
2008-10-25 02:50 . 2008-10-25 02:50 268 --ah----- C:\sqmdata09.sqm
2008-10-25 02:50 . 2008-10-25 02:50 244 --ah----- C:\sqmnoopt09.sqm
2008-10-25 02:38 . 2008-10-25 02:38 268 --ah----- C:\sqmdata08.sqm
2008-10-25 02:38 . 2008-10-25 02:38 244 --ah----- C:\sqmnoopt08.sqm
2008-10-25 02:22 . 2008-10-25 02:22 268 --ah----- C:\sqmdata07.sqm
2008-10-25 02:22 . 2008-10-25 02:22 244 --ah----- C:\sqmnoopt07.sqm
2008-10-25 01:54 . 2008-10-26 23:30 268 --ah----- C:\sqmdata06.sqm
2008-10-25 01:54 . 2008-10-26 23:30 244 --ah----- C:\sqmnoopt06.sqm
2008-10-25 01:21 . 2008-10-26 23:04 268 --ah----- C:\sqmdata05.sqm
2008-10-25 01:21 . 2008-10-26 23:04 244 --ah----- C:\sqmnoopt05.sqm
2008-10-24 22:20 . 2008-10-26 22:44 268 --ah----- C:\sqmdata04.sqm
2008-10-24 22:20 . 2008-10-26 22:44 244 --ah----- C:\sqmnoopt04.sqm
2008-10-24 22:08 . 2008-10-26 23:03 3,072,054 --a------ C:\WINDOWS\BricoPack Wallpaper.bmp
2008-10-24 22:08 . 2008-10-26 23:04 71,489 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-10-24 22:08 . 2008-10-26 22:42 268 --ah----- C:\sqmdata03.sqm
2008-10-24 22:08 . 2008-10-26 22:42 244 --ah----- C:\sqmnoopt03.sqm
2008-10-24 22:06 . 2008-10-26 23:01 <DIR> d-------- C:\WINDOWS\BricoPacks
2008-10-24 09:52 . 2008-10-26 13:38 268 --ah----- C:\sqmdata02.sqm
2008-10-24 09:52 . 2008-10-26 13:38 244 --ah----- C:\sqmnoopt02.sqm
2008-10-24 03:45 . 2008-10-24 03:45 <DIR> d---s---- C:\Documents and Settings\vip\UserData
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-30 00:05 155,995 ----a-w C:\WINDOWS\java\Packages\4RJ7JT7V.ZIP
2008-10-24 22:13 --------- d-----w C:\Program Files\Kaspersky Lab
2008-10-24 19:08 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-10-24 18:58 --------- d-----w C:\Program Files\Yahoo!
2008-10-24 02:10 --------- d-----w C:\Program Files\CCleaner
2008-10-24 01:46 --------- d-----w C:\Documents and Settings\vip\Application Data\ATI
2008-10-24 01:38 --------- d-----w C:\Program Files\ATI Technologies
2008-10-24 01:37 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-24 01:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-24 01:06 --------- d-----w C:\Program Files\Microsoft.NET
2008-10-24 00:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-24 00:23 --------- d-----w C:\Program Files\MSN Messenger
2008-10-23 23:44 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-15 15:24 1,846,272 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-14 13:20 2,146,816 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:20 2,025,472 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-07 20:27 253,952 ----a-w C:\WINDOWS\system32\es.dll
.
------- Sigcheck -------
2008-04-14 20:29 698880 42d872d207f9f5d278205234dcf92a7b C:\WINDOWS\system32\wininet.dll
2008-04-14 20:29 698880 42d872d207f9f5d278205234dcf92a7b C:\WINDOWS\system32\dllcache\wininet.dll
2008-04-14 20:29 974848 5320ea6507cfa8abc92caf91cd2fc8a5 C:\WINDOWS\explorer.exe
2008-04-14 20:29 974848 5320ea6507cfa8abc92caf91cd2fc8a5 C:\WINDOWS\system32\dllcache\explorer.exe
2007-07-30 19:19 68440 84d9a61860272d6177d46c86b8431557 C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 68440 84d9a61860272d6177d46c86b8431557 C:\WINDOWS\system32\dllcache\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-09-15 2606512]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2006-03-01 90112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="C:\WINDOWS\sm56hlpr.exe" [2006-03-21 544768]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-10-27 185872]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-10-30 136600]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-30 C:\WINDOWS\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [2006-05-16 C:\WINDOWS\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
C:\Documents and Settings\vip\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
TransBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-06-01 65536]
C:\DOCUME~1\ALLUSE~1\A007~1\7D39~1\D51D~1\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-05-22 2756608]
LaunchU3.exe.lnk - C:\WINDOWS\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe [2008-10-28 22486]
C:\DOCUME~1\vip\A007~1\7D39~1\D51D~1\
TransBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-06-01 65536]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
--a------ 2006-05-10 10:12 90112 C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-30 152984]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;C:\WINDOWS\System32\StkCSrv.exe [2007-04-19 24576]
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;C:\WINDOWS\system32\DRIVERS\l251x86.sys [2007-08-21 30208]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;C:\WINDOWS\system32\Drivers\StkCMini.sys [2007-06-06 1260672]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ed51480-a512-11dd-9aab-001e8c43cf0b}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
*Newly Created Service* - JAVAQUICKSTARTERSERVICE
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R1 -: HKCU-Internet Settings,ProxyServer = 212.93.193.87:8080
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O16 -: Microsoft XML Parser for Java -
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-30 14:22:39
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-30 14:23:19
ComboFix-quarantined-files.txt 2008-10-30 11:23:17
Pre-Run: 71,152,902,144 bytes free
Post-Run: 72,575,049,728 bytes free
208 --- E O F --- 2008-10-27 17:42:53