ComboFix 08-12-16.03 - طاغي 12/17/2008 20:25:39.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.735.479 [GMT 3:00]
Running from: d:\documents and settings\طاغي\سطح المكتب\برامج الحمايه\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_npf
((((((((((((((((((((((((( Files Created from 2008-11-17 to 2008-12-17 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-17 17:35 15,895,072 --sha-w d:\windows\system32\drivers\fidbox.dat
2008-12-17 17:33 732,448 --sha-w d:\windows\system32\drivers\fidbox2.dat
2008-12-17 17:30 71,732 --sha-w d:\windows\system32\drivers\fidbox2.idx
2008-12-17 17:30 221,168 --sha-w d:\windows\system32\drivers\fidbox.idx
2008-12-17 16:51 --------- d-----w d:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-17 14:51 --------- d-----w d:\documents and settings\طاغي\Application Data\cleaner
2008-12-15 17:49 --------- d-----w d:\program files\Hotspot_Shield
2008-12-15 17:49 --------- d-----w d:\program files\Conduit
2008-12-15 00:28 --------- d-----w d:\program files\Hotspot Shield
2008-12-11 06:30 --------- d-----w d:\documents and settings\طاغي\Application Data\CyberScrub
2008-12-11 00:08 --------- d-----w d:\program files\Golden Al-Wafi Translator
2008-12-10 14:47 --------- d-----w d:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-09 22:40 --------- d-----w d:\program files\Vuze
2008-12-09 20:51 --------- d-----w d:\documents and settings\طاغي\Application Data\Azureus
2008-12-09 12:21 --------- d-----w d:\documents and settings\All Users\Application Data\Apple Computer
2008-12-09 12:13 81,920 ----a-w d:\documents and settings\طاغي\Application Data\ezpinst.exe
2008-12-09 12:13 47,360 ----a-w d:\windows\system32\drivers\pcouffin.sys
2008-12-09 12:13 47,360 ----a-w d:\documents and settings\طاغي\Application Data\pcouffin.sys
2008-12-09 12:13 --------- d-----w d:\documents and settings\طاغي\Application Data\Vso
2008-12-09 11:22 --------- d-----w d:\program files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
2008-12-07 18:57 --------- d-----w d:\program files\Zone Labs
2008-12-05 23:51 --------- d-----w d:\program files\PC Tools Internet Security
2008-12-05 23:47 --------- d-----w d:\program files\Common Files\PC Tools
2008-12-05 23:47 --------- d-----w d:\documents and settings\All Users\Application Data\PC Tools
2008-12-05 23:46 --------- d---a-w d:\documents and settings\All Users\Application Data\TEMP
2008-12-05 23:44 --------- d-----w d:\program files\Browser Defender
2008-12-05 21:30 --------- d-----w d:\documents and settings\طاغي\Application Data\PCToolsSpamMonitorPlus
2008-12-05 21:30 --------- d-----w d:\documents and settings\طاغي\Application Data\PCToolsFirewallPlus
2008-12-05 18:20 --------- d-----w d:\program files\Common Files\InstallShield
2008-12-05 17:52 757,760 ----a-w d:\windows\system32\SkinCrafter.dll
2008-12-05 16:35 --------- d--h--w d:\program files\InstallShield Installation Information
2008-12-05 16:08 --------- d-----w d:\program files\Circle Developement
2008-12-05 16:07 --------- d-----w d:\documents and settings\طاغي\Application Data\BodyWipeNoun
2008-12-05 15:03 --------- d-----w d:\documents and settings\All Users\Application Data\Azureus
2008-12-05 14:08 --------- d-----w d:\program files\Windows Media Connect 2
2008-12-04 23:08 --------- d-----w d:\documents and settings\All Users\Application Data\Messenger Plus!
2008-12-04 23:05 --------- d-----w d:\program files\Windows Live
2008-12-04 23:04 --------- d-----w d:\documents and settings\All Users\Application Data\WLInstaller
2008-12-04 21:56 --------- d-----w d:\documents and settings\All Users\Application Data\STORE LESS JUGS SURF
2008-12-04 21:36 --------- d-----w d:\program files\BodyWipeNoun
2008-12-04 21:35 --------- d-----w d:\program files\Messenger Plus! Live
2008-12-04 19:33 --------- d-----w d:\program files\MSECACHE
2008-12-04 18:45 --------- d-----w d:\documents and settings\طاغي\Application Data\ADPHONE
2008-12-04 09:28 --------- d-----w d:\program files\MSN Messenger
2008-12-04 09:22 --------- d-----w d:\program files\Microsoft Office Outlook Connector
2008-12-04 09:09 --------- d-----w d:\program files\Windows Live Toolbar
2008-12-04 09:06 --------- d-----w d:\program files\Microsoft
2008-12-04 08:03 --------- d-----w d:\program files\Windows Installer Clean Up
2008-12-04 08:03 --------- d-----w d:\program files\Common Files\Windows Live
2008-12-04 07:29 410,976 ----a-w d:\windows\system32\deploytk.dll
2008-12-04 07:29 --------- d-----w d:\program files\Java
2008-12-04 07:01 --------- d-----w d:\program files\Yahoo!
2008-12-04 07:01 --------- d-----w d:\program files\CCleaner
2008-12-03 16:22 --------- d-----w d:\program files\IDA
2008-12-03 05:19 --------- d-----w d:\documents and settings\طاغي\Application Data\Internet Download Accelerator
2008-12-03 02:34 --------- d-----w d:\documents and settings\طاغي\Application Data\Media Player Classic
2008-12-03 02:30 2,223,653 ----a-w D:\mpc2kxp6490.zip
2008-12-02 19:50 --------- d-----w d:\program files\Common Files\Adobe
2008-12-02 18:31 75,921,920 ----a-w D:\ps55try.exe
2008-12-02 17:29 827,382 ----a-w D:\Trojan_u.zip
2008-12-02 17:14 985,989 ----a-w D:\MovieGear4.exe
2008-12-02 16:39 --------- d-----w d:\documents and settings\طاغي\Application Data\CursorArts
2008-12-02 16:36 6,766,448 ----a-w D:\imf_pro.exe
2008-12-02 14:16 40,073 ----a-w D:\patcher.zip
2008-12-02 14:09 --------- d-----w d:\program files\SWiSHmax
2008-12-02 14:05 9,783,685 ----a-w D:\SetupSwishmax_20050505.exe
2008-12-01 14:09 357,973 ----a-w D:\شطرنج.zip
2008-12-01 13:03 0 ---ha-w d:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-12-01 13:03 0 ---ha-w d:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-12-01 12:33 499,712 ----a-w d:\windows\system32\msvcp71.dll
2008-12-01 12:33 348,160 ----a-w d:\windows\system32\msvcr71.dll
2008-12-01 12:33 --------- d-----w d:\program files\Common Files\xing shared
2008-12-01 12:33 --------- d-----w d:\program files\Common Files\Real
2008-12-01 11:59 8,552 ----a-w d:\windows\system32\drivers\asctrm.sys
2008-12-01 11:59 --------- d-----w d:\program files\Real
2008-12-01 11:59 --------- d-----w d:\program files\aod
2008-11-30 16:28 --------- d-----w d:\documents and settings\طاغي\Application Data\HiYo
2008-11-30 00:41 --------- d-----w d:\program files\CEDP Stealer 6.0 for Messenger
2008-11-29 23:55 --------- d-----w d:\documents and settings\All Users\Application Data\iolo
2008-11-29 23:53 --------- d-----w d:\documents and settings\طاغي\Application Data\iolo
2008-11-29 21:19 --------- d-----w d:\program files\Microsoft SQL Server Compact Edition
2008-11-29 19:56 --------- dcsh--w d:\program files\Common Files\WindowsLiveInstaller
2008-11-23 15:13 --------- d-----w d:\documents and settings\All Users\Application Data\Bluetooth
2008-11-23 05:49 102,400 ----a-w d:\windows\system32\STemp_01.exe
2008-11-19 22:54 --------- d-----w d:\documents and settings\طاغي\Application Data\AntiSpywareGuard
2008-11-16 10:03 73,216 ----a-w d:\windows\ST6UNST.EXE
2008-11-16 10:03 172,032 ------w d:\windows\Setup1.exe
2008-11-14 16:30 --------- d-----w d:\program files\Windows Live Favorites
2008-11-14 16:28 --------- d-----w d:\documents and settings\All Users\Application Data\Windows Live Toolbar
2008-11-11 15:32 21,035 ----a-w d:\windows\system32\drivers\AegisP.sys
2008-11-11 15:31 --------- d-----w d:\program files\REALTEK RTL8187 Wireless LAN Driver and Utility
2008-10-24 11:21 455,296 ----a-w d:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w d:\windows\system32\gdi32.dll
2008-10-16 11:13 202,776 ----a-w d:\windows\system32\wuweb.dll
2008-10-16 11:13 1,809,944 ----a-w d:\windows\system32\wuaueng.dll
2008-10-16 11:12 561,688 ----a-w d:\windows\system32\wuapi.dll
2008-10-16 11:12 323,608 ----a-w d:\windows\system32\wucltui.dll
2008-10-16 11:09 92,696 ----a-w d:\windows\system32\cdm.dll
2008-10-16 11:09 51,224 ----a-w d:\windows\system32\wuauclt.exe
2008-10-16 11:09 43,544 ----a-w d:\windows\system32\wups2.dll
2006-10-11 08:04 61,036 ----a-w d:\program files\mozilla firefox\components\jar50.dll
2006-10-11 08:04 48,742 ----a-w d:\program files\mozilla firefox\components\jsd3250.dll
2006-10-11 08:05 29,313 ----a-w d:\program files\mozilla firefox\components\myspell.dll
2006-10-11 08:05 41,082 ----a-w d:\program files\mozilla firefox\components\spellchk.dll
2006-10-11 08:04 166,510 ----a-w d:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( snapshot_Mon 12-15-2008_11.17.51.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-08-13 15:39:20 71,680 ----a-w d:\windows\system32\admparse.dll
+ 2004-08-03 21:55:32 61,440 ----a-w d:\windows\system32\admparse.dll
- 2008-10-16 20:04:07 124,928 ----a-w d:\windows\system32\advpack.dll
+ 2004-08-03 21:55:32 99,840 ----a-w d:\windows\system32\advpack.dll
- 2008-04-14 15:59:33 35,328 ----a-w d:\windows\system32\corpol.dll
+ 2004-08-03 21:55:34 35,328 ----a-w d:\windows\system32\corpol.dll
- 2007-08-13 15:39:20 71,680 -c--a-w d:\windows\system32\dllcache\admparse.dll
+ 2004-08-03 21:55:32 61,440 -c--a-w d:\windows\system32\dllcache\admparse.dll
- 2008-10-16 20:04:07 124,928 -c--a-w d:\windows\system32\dllcache\advpack.dll
+ 2004-08-03 21:55:32 99,840 -c--a-w d:\windows\system32\dllcache\advpack.dll
+ 2004-08-03 21:55:34 35,328 ----a-w d:\windows\system32\dllcache\corpol.dll
- 2007-08-13 15:54:10 33,792 -c--a-w d:\windows\system32\dllcache\custsat.dll
+ 2004-08-03 21:55:34 28,672 -c--a-w d:\windows\system32\dllcache\custsat.dll
- 2008-10-16 20:04:07 347,136 -c--a-w d:\windows\system32\dllcache\dxtmsft.dll
+ 2008-08-20 05:36:11 357,888 -c--a-w d:\windows\system32\dllcache\dxtmsft.dll
- 2008-10-16 20:04:07 214,528 -c--a-w d:\windows\system32\dllcache\dxtrans.dll
+ 2008-08-20 05:36:12 205,312 -c--a-w d:\windows\system32\dllcache\dxtrans.dll
- 2008-10-16 20:04:08 133,120 -c--a-w d:\windows\system32\dllcache\extmgr.dll
+ 2008-08-20 05:36:12 55,808 -c--a-w d:\windows\system32\dllcache\extmgr.dll
- 2007-08-13 15:18:02 60,416 -c--a-w d:\windows\system32\dllcache\hmmapi.dll
+ 2004-08-03 21:55:38 38,912 -c--a-w d:\windows\system32\dllcache\hmmapi.dll
- 2008-10-16 13:09:53 70,656 -c--a-w d:\windows\system32\dllcache\ie4uinit.exe
+ 2004-08-03 21:56:16 34,304 -c--a-w d:\windows\system32\dllcache\ie4uinit.exe
- 2008-10-16 20:04:08 153,088 -c--a-w d:\windows\system32\dllcache\ieakeng.dll
+ 2004-08-03 21:55:38 139,264 -c--a-w d:\windows\system32\dllcache\ieakeng.dll
- 2008-10-16 20:04:08 230,400 -c--a-w d:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-03 21:55:38 216,064 -c--a-w d:\windows\system32\dllcache\ieaksie.dll
- 2008-10-15 07:04:53 161,792 -c--a-w d:\windows\system32\dllcache\ieakui.dll
+ 2001-09-19 12:00:00 221,184 -c--a-w d:\windows\system32\dllcache\ieakui.dll
- 2008-10-16 20:04:09 384,512 -c--a-w d:\windows\system32\dllcache\iedkcs32.dll
+ 2004-08-03 21:55:38 323,584 -c--a-w d:\windows\system32\dllcache\iedkcs32.dll
- 2007-08-13 15:44:02 69,120 -c--a-w d:\windows\system32\dllcache\iedw.exe
+ 2008-08-19 09:30:39 18,432 -c--a-w d:\windows\system32\dllcache\iedw.exe
+ 2004-08-03 21:55:38 81,920 ----a-w d:\windows\system32\dllcache\ieencode.dll
- 2007-08-13 15:54:10 191,488 -c--a-w d:\windows\system32\dllcache\iepeers.dll
+ 2008-08-20 05:36:12 250,880 -c--a-w d:\windows\system32\dllcache\iepeers.dll
- 2008-10-16 20:04:12 44,544 -c--a-w d:\windows\system32\dllcache\iernonce.dll
+ 2004-08-03 21:55:38 48,128 -c--a-w d:\windows\system32\dllcache\iernonce.dll
- 2007-08-13 15:39:12 55,296 -c--a-w d:\windows\system32\dllcache\iesetup.dll
+ 2004-08-03 21:55:38 62,976 -c--a-w d:\windows\system32\dllcache\iesetup.dll
- 2008-10-15 07:06:26 633,632 -c--a-w d:\windows\system32\dllcache\iexplore.exe
+ 2004-08-03 21:56:16 93,184 -c--a-w d:\windows\system32\dllcache\iexplore.exe
- 2007-08-13 15:36:06 36,352 -c--a-w d:\windows\system32\dllcache\imgutil.dll
+ 2004-08-03 21:55:38 35,840 -c--a-w d:\windows\system32\dllcache\imgutil.dll
- 2007-08-13 15:39:02 92,672 -c--a-w d:\windows\system32\dllcache\inseng.dll
+ 2008-08-20 05:36:12 96,256 -c--a-w d:\windows\system32\dllcache\inseng.dll
- 2008-05-09 10:53:39 512,000 -c----w d:\windows\system32\dllcache\jscript.dll
+ 2007-12-18 14:41:00 450,560 -c--a-w d:\windows\system32\dllcache\jscript.dll
- 2008-10-16 20:04:13 27,648 -c--a-w d:\windows\system32\dllcache\jsproxy.dll
+ 2008-08-20 05:36:14 16,384 -c--a-w d:\windows\system32\dllcache\jsproxy.dll
- 2007-08-13 15:44:18 40,960 -c--a-w d:\windows\system32\dllcache\licmgr10.dll
+ 2004-08-03 21:55:40 22,016 -c--a-w d:\windows\system32\dllcache\licmgr10.dll
- 2007-08-13 15:32:30 45,568 -c--a-w d:\windows\system32\dllcache\mshta.exe
+ 2004-08-03 21:56:22 29,184 -c--a-w d:\windows\system32\dllcache\mshta.exe
- 2008-10-16 22:34:18 3,593,216 -c--a-w d:\windows\system32\dllcache\mshtml.dll
+ 2008-08-20 05:36:17 3,081,216 -c--a-w d:\windows\system32\dllcache\mshtml.dll
- 2008-10-16 20:04:16 477,696 -c--a-w d:\windows\system32\dllcache\mshtmled.dll
+ 2008-08-20 05:36:14 449,024 -c--a-w d:\windows\system32\dllcache\mshtmled.dll
- 2007-08-13 15:01:12 48,128 -c--a-w d:\windows\system32\dllcache\mshtmler.dll
+ 2004-08-03 21:53:52 56,832 -c--a-w d:\windows\system32\dllcache\mshtmler.dll
- 2007-08-13 15:54:10 156,160 -c--a-w d:\windows\system32\dllcache\msls31.dll
+ 2001-09-19 12:00:00 146,432 -c--a-w d:\windows\system32\dllcache\msls31.dll
- 2008-10-16 20:04:17 193,024 -c--a-w d:\windows\system32\dllcache\msrating.dll
+ 2008-08-20 05:36:12 146,432 -c--a-w d:\windows\system32\dllcache\msrating.dll
- 2008-10-16 20:04:17 671,232 -c--a-w d:\windows\system32\dllcache\mstime.dll
+ 2008-08-20 05:36:12 532,480 -c--a-w d:\windows\system32\dllcache\mstime.dll
- 2008-10-16 20:04:17 102,912 -c--a-w d:\windows\system32\dllcache\occache.dll
+ 2004-08-03 21:55:46 96,256 -c--a-w d:\windows\system32\dllcache\occache.dll
- 2008-10-16 20:04:17 44,544 -c--a-w d:\windows\system32\dllcache\pngfilt.dll
+ 2008-08-20 05:36:12 39,424 -c--a-w d:\windows\system32\dllcache\pngfilt.dll
- 2008-10-16 20:04:17 105,984 -c--a-w d:\windows\system32\dllcache\url.dll
+ 2004-08-03 21:55:54 48,640 -c--a-w d:\windows\system32\dllcache\url.dll
- 2008-10-16 20:04:18 1,160,192 -c--a-w d:\windows\system32\dllcache\urlmon.dll
+ 2008-08-20 05:36:15 614,912 -c--a-w d:\windows\system32\dllcache\urlmon.dll
- 2008-05-09 10:53:40 430,080 -c----w d:\windows\system32\dllcache\vbscript.dll
+ 2007-12-18 14:41:00 417,792 -c--a-w d:\windows\system32\dllcache\vbscript.dll
- 2008-05-27 17:23:58 765,952 -c--a-w d:\windows\system32\dllcache\vgx.dll
+ 2004-08-03 21:55:54 848,384 -c--a-w d:\windows\system32\dllcache\vgx.dll
- 2008-10-16 20:04:18 233,472 -c--a-w d:\windows\system32\dllcache\webcheck.dll
+ 2004-08-03 21:55:58 276,480 -c--a-w d:\windows\system32\dllcache\webcheck.dll
- 2008-10-16 20:04:19 826,368 -c--a-w d:\windows\system32\dllcache\wininet.dll
+ 2008-08-20 05:36:13 657,920 -c--a-w d:\windows\system32\dllcache\wininet.dll
- 2008-10-16 20:04:07 347,136 ----a-w d:\windows\system32\dxtmsft.dll
+ 2008-08-20 05:36:11 357,888 ----a-w d:\windows\system32\dxtmsft.dll
- 2008-10-16 20:04:07 214,528 ----a-w d:\windows\system32\dxtrans.dll
+ 2008-08-20 05:36:12 205,312 ----a-w d:\windows\system32\dxtrans.dll
- 2008-10-16 20:04:08 133,120 ----a-w d:\windows\system32\extmgr.dll
+ 2008-08-20 05:36:12 55,808 ----a-w d:\windows\system32\extmgr.dll
- 2008-10-16 13:09:53 70,656 ----a-w d:\windows\system32\ie4uinit.exe
+ 2004-08-03 21:56:16 34,304 ----a-w d:\windows\system32\ie4uinit.exe
- 2008-10-16 20:04:08 153,088 ----a-w d:\windows\system32\ieakeng.dll
+ 2004-08-03 21:55:38 139,264 ----a-w d:\windows\system32\ieakeng.dll
- 2008-10-16 20:04:08 230,400 ----a-w d:\windows\system32\ieaksie.dll
+ 2004-08-03 21:55:38 216,064 ----a-w d:\windows\system32\ieaksie.dll
- 2008-10-15 07:04:53 161,792 ----a-w d:\windows\system32\ieakui.dll
+ 2001-09-19 12:00:00 221,184 ----a-w d:\windows\system32\ieakui.dll
- 2008-10-16 20:04:09 384,512 ----a-w d:\windows\system32\iedkcs32.dll
+ 2004-08-03 21:55:38 323,584 ----a-w d:\windows\system32\iedkcs32.dll
- 2008-04-14 15:59:35 81,920 ----a-w d:\windows\system32\ieencode.dll
+ 2004-08-03 21:55:38 81,920 ----a-w d:\windows\system32\ieencode.dll
- 2007-08-13 15:54:10 191,488 ----a-w d:\windows\system32\iepeers.dll
+ 2008-08-20 05:36:12 250,880 ----a-w d:\windows\system32\iepeers.dll
- 2008-10-16 20:04:12 44,544 ----a-w d:\windows\system32\iernonce.dll
+ 2004-08-03 21:55:38 48,128 ----a-w d:\windows\system32\iernonce.dll
- 2007-08-13 15:39:12 55,296 ----a-w d:\windows\system32\iesetup.dll
+ 2004-08-03 21:55:38 62,976 ----a-w d:\windows\system32\iesetup.dll
- 2007-08-13 15:36:06 36,352 ----a-w d:\windows\system32\imgutil.dll
+ 2004-08-03 21:55:38 35,840 ----a-w d:\windows\system32\imgutil.dll
- 2007-08-13 15:39:02 92,672 ----a-w d:\windows\system32\inseng.dll
+ 2008-08-20 05:36:12 96,256 ----a-w d:\windows\system32\inseng.dll
- 2008-05-09 10:53:39 512,000 ----a-w d:\windows\system32\jscript.dll
+ 2007-12-18 14:41:00 450,560 ----a-w d:\windows\system32\jscript.dll
- 2008-10-16 20:04:13 27,648 ----a-w d:\windows\system32\jsproxy.dll
+ 2008-08-20 05:36:14 16,384 ----a-w d:\windows\system32\jsproxy.dll
- 2007-08-13 15:44:18 40,960 ----a-w d:\windows\system32\licmgr10.dll
+ 2004-08-03 21:55:40 22,016 ----a-w d:\windows\system32\licmgr10.dll
- 2007-08-13 15:32:30 45,568 ----a-w d:\windows\system32\mshta.exe
+ 2004-08-03 21:56:22 29,184 ----a-w d:\windows\system32\mshta.exe
- 2008-10-16 22:34:18 3,593,216 ----a-w d:\windows\system32\mshtml.dll
+ 2008-08-20 05:36:17 3,081,216 ----a-w d:\windows\system32\mshtml.dll
- 2008-10-16 20:04:16 477,696 ----a-w d:\windows\system32\mshtmled.dll
+ 2008-08-20 05:36:14 449,024 ----a-w d:\windows\system32\mshtmled.dll
- 2007-08-13 15:01:12 48,128 ----a-w d:\windows\system32\mshtmler.dll
+ 2004-08-03 21:53:52 56,832 ----a-w d:\windows\system32\mshtmler.dll
- 2007-08-13 15:54:10 156,160 ----a-w d:\windows\system32\msls31.dll
+ 2001-09-19 12:00:00 146,432 ----a-w d:\windows\system32\msls31.dll
- 2008-10-16 20:04:17 193,024 ----a-w d:\windows\system32\msrating.dll
+ 2008-08-20 05:36:12 146,432 ----a-w d:\windows\system32\msrating.dll
- 2008-10-16 20:04:17 671,232 ----a-w d:\windows\system32\mstime.dll
+ 2008-08-20 05:36:12 532,480 ----a-w d:\windows\system32\mstime.dll
- 2008-10-16 20:04:17 102,912 ----a-w d:\windows\system32\occache.dll
+ 2004-08-03 21:55:46 96,256 ----a-w d:\windows\system32\occache.dll
- 2008-10-16 20:04:17 44,544 ----a-w d:\windows\system32\pngfilt.dll
+ 2008-08-20 05:36:12 39,424 ----a-w d:\windows\system32\pngfilt.dll
- 2008-10-16 20:04:17 105,984 ----a-w d:\windows\system32\url.dll
+ 2004-08-03 21:55:54 48,640 ----a-w d:\windows\system32\url.dll
- 2008-10-16 20:04:18 1,160,192 ----a-w d:\windows\system32\urlmon.dll
+ 2008-08-20 05:36:15 614,912 ----a-w d:\windows\system32\urlmon.dll
- 2008-05-09 10:53:40 430,080 ----a-w d:\windows\system32\vbscript.dll
+ 2007-12-18 14:41:00 417,792 ----a-w d:\windows\system32\vbscript.dll
- 2008-10-16 20:04:18 233,472 ----a-w d:\windows\system32\webcheck.dll
+ 2004-08-03 21:55:58 276,480 ----a-w d:\windows\system32\webcheck.dll
- 2008-10-16 20:04:19 826,368 ----a-w d:\windows\system32\wininet.dll
+ 2008-08-20 05:36:13 657,920 ----a-w d:\windows\system32\wininet.dll
- 2008-12-11 10:24:08 4,212 ---h--w d:\windows\system32\zllictbl.dat
+ 2008-12-17 12:48:06 4,212 ---h--w d:\windows\system32\zllictbl.dat
+ 2008-12-17 17:32:54 16,384 ----atw d:\windows\Temp\Perflib_Perfdata_11c.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"MsnMsgr"="d:\program files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"MSMSGS"="d:\program files\Messenger\msmsgs.exe" [04/14/2008 06:59 PM 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [08/24/2007 07:00 AM 33648]
"TkBellExe"="d:\program files\Common Files\Real\Update_OB\realsched.exe" [12/01/2008 03:33 PM 185872]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [12/04/2008 10:29 AM 136600]
"ZoneAlarm Client"="d:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [11/14/2007 04:05 PM 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
d:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.exe.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-02 113664]
REALTEK RTL8187 Wireless LAN Utility.lnk - d:\program files\REALTEK RTL8187 Wireless LAN Driver and Utility\RtWLan.exe [2008-11-11 737280]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"d:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Messenger\\msmsgs.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 oxser;OX16C95x Serial port driver;d:\windows\system32\DRIVERS\oxser.sys [2008-08-25 51169]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;d:\windows\system32\DRIVERS\klim5.sys [2007-04-04 24344]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;d:\windows\system32\DRIVERS\RTL8187.sys [2008-11-11 194304]
R3 SjyPkt;SjyPkt;\??\d:\windows\System32\Drivers\SjyPkt.sys [2008-11-11 13532]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - d:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
IE: Download ALL with IDA
IE: Download with IDA
IE: ت&صدير إلى Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 -: Microsoft XML Parser for Java -
d:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
d:\windows\system32\msvcrt.dll - d:\windows\system32\mfc42.dll
d:\windows\system32\olepro32.dll
d:\windows\Downloaded Program Files\imcv1.dll
O16 -: {6924091F-CD97-41E1-B1D4-D9079409D413}
hxxp://76.76.24.100/IMSCP/talk.cab
d:\windows\Downloaded Program Files\talk.inf
FF - ProfilePath - d:\documents and settings\طاغي\Application Data\Mozilla\Firefox\Profiles\n6esbnl1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-17 20:33:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1620)
d:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
d:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1676)
d:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll
d:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
- - - - - - - > 'explorer.exe'(3912)
d:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
d:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll
d:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
d:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
d:\program files\Hotspot Shield\bin\openvpnas.exe
d:\program files\Java\jre6\bin\jqs.exe
.
**************************************************************************
.
Completion time: 12/17/2008 20:38:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-17 17:38:10
ComboFix2.txt 2008-12-15 08:19:55
ComboFix3.txt 2008-12-10 02:17:13
Pre-Run: 616,851,968 bytes free
Post-Run: 600,952,320 bytes free
378 --- E O F --- 2008-12-10 14:47:38