ComboFix 09-03-23.01 - asas 03/25/2009 4:16:18.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.446.215 [GMT 3:00]
Running from: c:\documents and settings\asas\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
.
((((((((((((((((((((((((( Files Created from 2009-02-25 to 2009-03-25 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-24 22:19 24,791 ----a-w c:\documents and settings\asas\Application Data\Vbcn.dat
2009-03-24 05:08 --------- d-----w c:\documents and settings\All Users\Application Data\zyz Kaspersky Lab setup files
2009-03-16 21:23 --------- d-----w c:\program files\Microsoft Sync Framework
2009-03-16 21:19 --------- d-----w c:\program files\Microsoft
2009-03-16 21:18 --------- d-----w c:\program files\Windows Live SkyDrive
2009-03-11 03:26 --------- d-----w c:\program files\Common Files\Windows Live
2009-03-10 21:52 --------- d-----w c:\documents and settings\All Users\Application Data\Cast ping base frag
2009-03-10 21:51 --------- d-----w c:\program files\army option
2009-03-10 21:51 --------- d-----w c:\documents and settings\asas\Application Data\army option
2009-03-10 21:50 --------- d-----w c:\program files\Messenger Plus! Live
2009-02-17 18:22 --------- d-----w c:\program files\Azkary
2009-02-11 03:52 --------- d-----w c:\program files\tobah
2009-02-08 21:29 1,175,700 ----a-w c:\windows\system32\RainySs.scr
2009-02-08 21:26 --------- d-----w c:\program files\Rainy Screensaver
2009-02-06 16:43 307,576 ----a-w c:\windows\WLXPGSS.SCR
2009-02-06 15:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dash Body"="c:\docume~1\asas\APPLIC~1\ARMYOP~1\daleproxydoes.exe" [03/11/2009 12:50 AM 655360]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/03/2004 09:56 PM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Azkary"="c:\program files\Azkary\Azkary" [X]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [01/10/2009 09:30 PM 185896]
"Base frag grid bows"="c:\documents and settings\All Users\Application Data\Cast ping base frag\soap amen.exe" [03/25/2009 01:29 AM 806912]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/03/2004 09:56 PM 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^palstart.exe]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\palstart.exe
backup=c:\windows\pss\palstart.exeCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^asas^قائمة ابدأ^البرامج^بدء التشغيل^MutiKeyboard Driver.lnk]
path=c:\documents and settings\asas\قائمة ابدأ\البرامج\بدء التشغيل\MutiKeyboard Driver.lnk
backup=c:\windows\pss\MutiKeyboard Driver.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VModes]
VModes 1024 768 32 60 [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 08/03/2004 09:56 PM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 05/11/2005 11:12 PM 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
--a------ 12/03/2008 07:52 PM 399504 c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 08/04/2004 01:09 AM 1667584 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 02/06/2009 06:53 PM 3885408 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 04/26/2006 08:29 AM 237568 c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
--a------ 04/11/2006 05:52 PM 1409024 c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 11/07/2007 09:42 AM 155648 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 11/02/2004 08:24 PM 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 01/10/2009 09:30 PM 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-ra------ 05/17/2005 01:48 PM 77824 c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
-ra------ 03/07/2005 10:33 PM 53248 c:\windows\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
-ra------ 03/11/2005 12:33 PM 147456 c:\windows\system32\VTTrayp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2008-12-29 170640]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2008-12-29 15504]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{935AC426-9F73-D288-9D5F-26D1BD516FA3}]
c:\program files\Playae\Playae.exe s
.
Contents of the 'Scheduled Tasks' folder
2009-03-25 c:\windows\Tasks\A6F8687990C41DB9.job
- c:\docume~1\asas\applic~1\armyop~1\Grimnewerror.exe [03/11/2009 12:53 AM]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-AVP - c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uInternet Settings,ProxyServer = 212.62.97.20
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
DPF: {8C159DFD-DC9C-4077-B3B6-114A8D64B6D2} - hxxp://74.53.69.70/cp/files/talk08.cab
DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} - hxxp://209.11.243.139/ReadUid.CAB
DPF: {C171FF59-8C55-4796-A398-4F5D02B4C763} - hxxp://76.76.24.102/imscp/talks3n.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-03-25 04:17:33
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
c:\program files\INTERNET EXPLORER\IEXPLORE.EXE [1704] 0x84228DA0
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 03/25/2009 4:18:30
ComboFix-quarantined-files.txt 2009-03-25 01:18:30
Pre-Run: 19,725,418,496 bytes free
Post-Run: 20,670,087,168 bytes free
131