ComboFix 08-12-09.03 - mxm 12/11/2008 14:26:20.4 - NTFSx86Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.484 [GMT 3:00]Running from: c:\documents and settings\mxm\سطح المكتب\ComboFix.exe * Created a new restore point * Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).c:\program files\Windows Live\Messenger\msimg32.dllc:\windows\system32\tmp.reg.((((((((((((((((((((((((( Files Created from 2008-11-11 to 2008-12-11 ))))))))))))))))))))))))))))))).No new files created in this timespan.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2008-12-11 11:28 --------- d-----w c:\documents and settings\mxm\Application Data\DMCache2008-12-09 17:03 --------- d-----r c:\program files\Real2008-12-09 17:01 --------- d-----w c:\program files\DivX2008-12-09 17:01 --------- d-----r c:\program files\Wise Disk Cleaner2008-12-07 11:22 --------- d-----r c:\program files\Java2008-12-05 21:24 348,160 ----a-w c:\windows\system32\msvcr71.dll2008-12-05 21:08 --------- d-----r c:\program files\Windows Live2008-12-04 10:35 --------- d-----w c:\documents and settings\mxm\Application Data\Thinstall2008-12-01 11:46 --------- d-----r c:\program files\Internet Download Manager2008-12-01 11:41 --------- d-----w c:\documents and settings\mxm\Application Data\IDM2008-12-01 10:31 --------- d-----w c:\program files\Common Files\Elecard2008-11-28 16:10 --------- d-----w c:\documents and settings\All Users\Application Data\Bandoo2008-11-25 21:48 --------- d-----w c:\documents and settings\mxm\Application Data\Nokia Multimedia Player2008-11-25 20:24 410,976 ----a-w c:\windows\system32\deploytk.dll2008-11-24 23:29 --------- d-----w c:\documents and settings\All Users\Application Data\Alawar Stargaze2008-11-23 23:15 --------- d-----w c:\documents and settings\All Users\Application Data\Skype2008-11-23 22:46 --------- d-----w c:\documents and settings\mxm\Application Data\skypePM2008-11-21 18:46 --------- d-----r c:\program files\PC Connectivity Solution2008-11-20 13:54 --------- d-----w c:\documents and settings\All Users\Application Data\SweetIM2008-11-17 11:18 --------- d-----w c:\program files\Common Files\PCSuite2008-11-17 11:18 --------- d-----w c:\program files\Common Files\Nokia2008-11-17 11:18 --------- d-----r c:\program files\Nokia2008-11-15 20:09 --------- d-----w c:\documents and settings\All Users\Application Data\Installations2008-11-10 19:58 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP2008-11-08 11:39 --------- d-----w c:\documents and settings\mxm\Application Data\Uniblue2008-11-06 19:41 --------- d-----r c:\program files\SimpleCenter2008-10-31 21:03 --------- d-----r c:\program files\McAfee2008-10-31 19:52 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee2008-10-31 19:51 --------- d-----w c:\program files\Common Files\McAfee2008-10-31 19:51 --------- d-----w c:\program files\Common Files\Cisco Systems2008-10-29 11:02 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf2008-10-29 11:02 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf2008-10-29 08:36 --------- d-----w c:\documents and settings\mxm\Application Data\TigerPlayer2008-10-26 12:59 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files2008-10-25 21:26 --------- d-----w c:\documents and settings\mxm\Application Data\cleaner2008-10-24 12:19 --------- d-----w c:\documents and settings\mxm\Application Data\PC Suite2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys2008-10-24 11:21 455,296 ------w c:\windows\system32\dllcache\mrxsmb.sys2008-10-23 20:09 --------- d-----w c:\documents and settings\mxm\Application Data\dvdcss2008-10-23 13:32 --------- d-----w c:\documents and settings\mxm\Application Data\Nokia2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll2008-10-23 12:36 286,720 ------w c:\windows\system32\dllcache\gdi32.dll2008-10-22 09:37 --------- d-----r c:\program files\Folderico2008-10-20 13:20 21,275 ----a-w c:\windows\system32\drivers\AegisP.sys2008-10-20 13:20 --------- d-----w c:\documents and settings\Administrator\Application Data\Intel2008-10-19 20:55 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!2008-10-19 13:04 --------- d-----r c:\program files\MSECACHE2008-10-19 13:04 --------- d-----r c:\program files\Messenger Plus! Live2008-10-19 12:36 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller2008-10-19 12:35 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller2008-10-19 11:25 --------- d-----r c:\program files\Windows Installer Clean Up2008-10-18 09:31 --------- d-----w c:\documents and settings\mxm\Application Data\AIMP2008-10-16 22:34 3,593,216 ------w c:\windows\system32\dllcache\mshtml.dll2008-10-16 13:11 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe2008-10-16 13:09 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe2008-10-16 11:13 202,776 ----a-w c:\windows\system32\wuweb.dll2008-10-16 11:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll2008-10-16 11:12 561,688 ----a-w c:\windows\system32\wuapi.dll2008-10-16 11:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll2008-10-16 11:12 323,608 ----a-w c:\windows\system32\wucltui.dll2008-10-16 11:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll2008-10-16 11:09 92,696 ----a-w c:\windows\system32\cdm.dll2008-10-16 11:09 51,224 ----a-w c:\windows\system32\wuauclt.exe2008-10-16 11:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe2008-10-16 11:09 43,544 ----a-w c:\windows\system32\wups2.dll2008-10-16 11:08 34,328 ----a-w c:\windows\system32\wups.dll2008-10-16 11:06 268,648 ----a-w c:\windows\system32\mucltui.dll2008-10-16 11:06 208,744 ----a-w c:\windows\system32\muweb.dll2008-10-15 21:23 --------- d-----w c:\documents and settings\All Users\Application Data\ESET2008-10-15 19:57 --------- d-----w c:\documents and settings\mxm\Application Data\ESET2008-10-15 16:35 337,408 ------w c:\windows\system32\dllcache\netapi32.dll2008-10-15 07:06 633,632 ------w c:\windows\system32\dllcache\iexplore.exe2008-10-15 07:04 161,792 ------w c:\windows\system32\dllcache\ieakui.dll2008-10-14 08:55 --------- d-----r c:\program files\Conduit2008-10-12 21:52 --------- d-----w c:\documents and settings\mxm\Application Data\TeamViewer2008-10-12 09:43 --------- d-----r c:\program files\SHOUTcast Source2008-10-12 08:12 --------- d-----r c:\program files\Sun2008-10-11 11:27 --------- d-----r c:\program files\CCleaner2008-10-11 11:25 --------- d-----r c:\program files\VS Revo Group2008-10-05 21:13 63,074 ----a-w c:\windows\BricoPackUninst.cmd2008-10-05 21:13 6,102 ----a-w c:\windows\BricoPackFoldersDelete.cmd2008-10-05 21:13 218,624 ----a-w c:\windows\system32\uxtheme.dll2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll2008-10-03 10:03 247,326 ------w c:\windows\system32\dllcache\strmdll.dll2008-10-02 00:13 99 --sh--w c:\program files\desktop.ini2008-10-02 00:13 15,086 --sh--w c:\program files\ShedkoFolderico3_21526755.ico2008-10-02 00:05 15,086 --sh--w c:\program files\Common Files\ShedkoFolderico3_1938715116.ico2008-10-02 00:05 101 --sh--w c:\program files\Common Files\desktop.ini2008-10-01 21:37 81,920 ----a-w c:\documents and settings\mxm\Application Data\ezpinst.exe2008-10-01 21:37 47,360 ----a-w c:\documents and settings\mxm\Application Data\pcouffin.sys2008-09-30 13:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll2008-09-29 05:07 67,904 ----a-w c:\windows\system32\mfevtps.exe2008-09-29 05:07 19,480 ----a-w c:\windows\system32\MFEOtlk.dll2008-09-19 04:21 155,995 ----a-w c:\windows\java\Packages\NBPJVP7Z.ZIP2008-09-15 15:24 1,846,272 ----a-w c:\windows\system32\win32k.sys2008-09-12 10:44 206,256 -c--a-w c:\windows\system32\idmmbc.dll2008-08-22 20:59 16,384 --sha-w c:\windows\system32\config\systemprofile\s\index.dat2008-08-22 20:59 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat2008-08-22 20:59 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082220080823\index.dat2008-08-22 20:59 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\.IE5\index.dat.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [04/15/2008 12:29 AM 15360]"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 11:34 AM 5724184]"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [12/01/2006 12:03 PM 204288]"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [10/11/2007 03:15 AM 802816][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [12/06/2008 12:23 AM 185872]"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [11/25/2008 11:24 PM 136600]"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [04/14/2006 11:51 AM 667718]"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [04/14/2006 11:52 AM 602182]"igfxtray"="c:\windows\system32\igfxtray.exe" [06/13/2006 09:57 AM 94208]"igfxpers"="c:\windows\system32\igfxpers.exe" [06/13/2006 09:57 AM 118784]"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [06/13/2006 09:57 AM 77824]"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [04/14/2006 11:56 AM 569413]"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [07/19/2006 09:41 AM 53248]"SkyTel"="SkyTel.EXE" [07/19/2006 09:42 AM 2879488 c:\windows\SkyTel.exe]"RTHDCPL"="RTHDCPL.EXE" [07/19/2006 09:42 AM 16248320 c:\windows\RTHDCPL.exe][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [04/15/2008 12:29 AM 15360]"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [11/07/2007 05:35 PM 1294336]c:\documents and settings\All Users\çںê، ں§ڑ\ںé©ںê¤\§ک ں颬نïé\Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-01-17 618557][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]"UIHost"="c:\\WINDOWS\\system32\\logonui.exe"[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]"vidc.hfyu"= huffyuv.dll"msacm.l3codec"= l3codecp.acm"msacm.divxa32"= DivXa32.acm"vidc.tscc"= c:\progra~1\MpcStar\Codecs\tscc\tsccvid.dll[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]@="Service"[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^SnagIt 9.lnk]backup=c:\windows\pss\SnagIt 9.lnkCommon Startup[HKEY_LOCAL_MACHINE\software\microsoft\security center]"AntiVirusOverride"=dword:00000001"FirewallOverride"=dword:00000001[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\system32\\sessmgr.exe"="c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"="c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe"="c:\\Program Files\\Real\\RealPlayer\\realplay.exe"="c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="c:\\Program Files\\Java\\jre6\\bin\\java.exe"=[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"8340:TCP"= 8340:TCP:BitComet 8340 TCP"8340:UDP"= 8340:UDP:BitComet 8340 UDPR0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]R0 ulsata2;ulsata2;c:\windows\system32\drivers\ulsata2.sys [2008-05-07 124928]R2 McAfeeEngineService;McAfee Engine Service;"c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe" [2008-09-29 19456]R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2008-10-31 67904]R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]S2 Bandoo Coordinator;Bandoo Coordinator;"c:\progra~1\Bandoo\Bandoo.exe" []S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2008-10-31 64432][HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]"c:\program files\Windows Sidebar\sidebar.exe" /RegServer.s of the 'Scheduled Tasks' folder2008-12-10 c:\windows\Tasks\GoogleUpdateTaskUser.job- c:\documents and settings\mxm\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [].- - - - ORPHANS REMOVED - - - -WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)HKCU-Run-X'nBeep - c:\program files\X'nBeep 1.1\XnBeep.exeHKCU-Run-45170 - C:\WINDOWS/45170.exeHKLM-Run-NSLauncher - c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe.------- Supplementary Scan -------.uStart Page = hxxp://www.google.com.sa/uInternet Settings,ProxyOverride = localIE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htmIE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htmIE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htmO16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cabc:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osdFireFox -: Profile - c:\documents and settings\mxm\Application Data\Mozilla\Firefox\Profiles\8s2im1vu.default\FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.sweetim.com/search.asp?src=2&q=FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://home.sweetim.comFF -: plugin - c:\program files\DivX\DivX Uploader\npUpload.dllFF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dllFF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dllFF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dllFF -: plugin - c:\program files\Real\RhapsodyPlayerEngine\nprhapengine.dllFF -: plugin - c:\windows\system32\C2MP\npdivx32.dll.**************************************************************************catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
scan 2008-12-11 14:28:15Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes ... scanning hidden autostart entries ...scanning hidden files ... scan completed successfullyhidden files: 0**************************************************************************.Completion time: 12/11/2008 14:29:08ComboFix-quarantined-files.txt 2008-12-11 11:29:04Pre-Run: 46,176,415,744 bytes freePost-Run: 46,180,331,520 bytes free226 --- E O F --- 2008-12-11 11:14:02