السلام عليكم معليش على التعب وهذا التقرير كيف ممتاز ComboFix 09-04-17.01 - aseer 04/16/2009 3:24.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.479.236 [GMT 3:00]
Running from: c:\documents and settings\aseer\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2009-03-16 to 2009-04-16 )))))))))))))))))))))))))))))))
.
2009-04-15 08:43 . 2009-04-15 08:43 -------- d-----w c:\documents and settings\All Users\Application Data\TVU Networks
2009-04-15 08:26 . 2009-04-15 08:26 -------- d-----w c:\documents and settings\aseer\Application Data\Uniblue
2009-04-15 08:23 . 2009-04-15 08:23 -------- dc-h--w c:\documents and settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
2009-04-15 07:33 . 2009-04-15 07:33 -------- d--h--w c:\windows\system32\GroupPolicy
2009-04-15 07:13 . 2009-04-15 07:13 -------- d-----w c:\documents and settings\aseer\Application Data\DivX
2009-04-15 06:36 . 2009-04-15 06:36 -------- d-----w c:\documents and settings\aseer\Application Data\TVU networks
2009-04-15 06:36 . 2009-04-15 06:36 -------- d-----w c:\documents and settings\aseer\Local Settings\Application Data\TVU Networks
2009-04-15 06:35 . 2009-04-15 06:35 -------- d-----w c:\documents and settings\aseer\LocalLow
2009-04-15 05:00 . 2009-04-15 05:00 -------- d-----w c:\documents and settings\aseer\Application Data\CyberScrub
2009-04-15 05:00 . 2009-04-15 05:11 -------- d-----w c:\documents and settings\aseer\Application Data\cleaner
2009-04-15 04:05 . 2009-04-15 04:05 -------- d-----w c:\windows\system32\LogFiles
2009-04-15 02:45 . 2009-04-15 03:08 -------- d-----w C:\LINEZERO
2009-04-14 16:16 . 2009-04-14 16:16 -------- d-----w c:\documents and settings\aseer\DoctorWeb
2009-04-11 17:05 . 2006-06-29 10:07 14048 ------w c:\windows\system32\spmsg2.dll
2009-04-11 16:52 . 2009-04-11 17:04 -------- d-----w c:\windows\system32\XPSViewer
2009-04-11 16:50 . 2008-07-06 12:06 89088 -c----w c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-04-11 16:50 . 2008-07-06 12:06 117760 ------w c:\windows\system32\prntvpt.dll
2009-04-11 16:50 . 2008-07-06 10:50 597504 -c----w c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-04-11 16:50 . 2009-04-11 16:51 -------- d-----w C:\8cc09a7289e2c0b07cd4b68156
2009-04-11 16:50 . 2008-07-06 12:06 575488 -c----w c:\windows\system32\dllcache\xpsshhdr.dll
2009-04-11 16:50 . 2008-07-06 12:06 575488 ------w c:\windows\system32\xpsshhdr.dll
2009-04-11 16:50 . 2008-07-06 12:06 1676288 -c----w c:\windows\system32\dllcache\xpssvcs.dll
2009-04-11 16:50 . 2008-07-06 12:06 1676288 ------w c:\windows\system32\xpssvcs.dll
2009-04-09 15:57 . 2009-04-09 15:57 10 ----a-w c:\windows\system32\810429tv4-test.jun
2009-04-09 13:17 . 2001-08-17 19:36 8704 -c--a-w c:\windows\system32\dllcache\kbdjpn.dll
2009-04-09 13:17 . 2001-08-17 19:36 8704 ----a-w c:\windows\system32\kbdjpn.dll
2009-04-09 13:17 . 2001-08-17 19:36 8192 -c--a-w c:\windows\system32\dllcache\kbdkor.dll
2009-04-09 13:17 . 2001-08-17 19:36 8192 ----a-w c:\windows\system32\kbdkor.dll
2009-04-09 13:17 . 2001-08-17 11:55 6144 -c--a-w c:\windows\system32\dllcache\kbd101c.dll
2009-04-09 13:17 . 2001-08-17 11:55 6144 ----a-w c:\windows\system32\kbd101c.dll
2009-04-09 13:17 . 2001-08-17 11:55 5632 -c--a-w c:\windows\system32\dllcache\kbd103.dll
2009-04-09 13:17 . 2001-08-17 11:55 5632 ----a-w c:\windows\system32\kbd103.dll
2009-04-09 13:17 . 2001-08-17 11:55 6144 -c--a-w c:\windows\system32\dllcache\kbd101b.dll
2009-04-09 13:17 . 2001-08-17 11:55 6144 ----a-w c:\windows\system32\kbd101b.dll
2009-04-09 13:17 . 2008-04-14 18:28 6144 -c--a-w c:\windows\system32\dllcache\kbd106.dll
2009-04-09 13:17 . 2008-04-14 18:28 6144 ----a-w c:\windows\system32\kbd106.dll
2009-04-09 07:26 . 2009-04-09 07:26 -------- d-----w c:\documents and settings\aseer\Local Settings\Application Data\MyDownloader
2009-04-09 03:02 . 2009-04-09 03:02 -------- d-----w c:\documents and settings\aseer\Application Data\FreeCall
2009-04-08 23:04 . 2009-04-08 23:04 -------- d-----w c:\documents and settings\aseer\Application Data\Thinstall
2009-04-08 22:24 . 2001-11-02 14:13 114688 ----a-w c:\windows\system32\qlm.dll
2009-04-08 22:24 . 2001-08-28 11:53 69632 ----a-w c:\windows\system32\d2hPopup.ocx
2009-04-08 22:11 . 2009-04-08 22:11 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-04-08 21:26 . 2009-04-08 21:26 -------- d-----w C:\Downloads
2009-04-08 20:51 . 2009-04-08 20:51 -------- d-----w c:\documents and settings\All Users\Application Data\GRETECH
2009-04-08 20:51 . 2009-04-08 20:51 -------- d-----w c:\documents and settings\aseer\Application Data\GRETECH
2009-04-06 11:36 . 2009-04-06 11:36 657 ----a-w c:\windows\explorer.exe.manifest
2009-04-06 05:45 . 1998-10-29 13:45 306688 ----a-w c:\windows\IsUninst.exe
2009-04-06 05:45 . 2009-04-06 05:45 -------- d-----w c:\documents and settings\aseer\WINDOWS
2009-04-06 05:45 . 2009-04-06 05:45 -------- d-----w C:\Ectaco
2009-04-02 07:40 . 2009-04-02 07:40 -------- d-----w c:\documents and settings\aseer\Application Data\Pegasys Inc
2009-04-02 07:24 . 2009-04-02 07:21 59488 ----a-w c:\windows\system32\GenSvcInst.exe
2009-04-02 07:24 . 2009-04-02 07:21 33408 ----a-w c:\windows\system32\drivers\CDRBSDRV.SYS
2009-04-02 07:24 . 2009-04-02 07:21 145504 ----a-w c:\windows\system32\bgsvcgen.exe
2009-04-02 06:57 . 2009-04-02 06:57 -------- d--h--w c:\windows\PIF
2009-03-25 15:31 . 2001-09-18 10:27 17664 -c--a-w c:\windows\system32\dllcache\sermouse.sys
2009-03-25 15:31 . 2001-09-18 10:27 17664 ----a-w c:\windows\system32\drivers\sermouse.sys
2009-03-25 06:01 . 2009-04-03 01:11 -------- d-----w c:\documents and settings\aseer\Application Data\Paltalk
2009-03-25 04:17 . 2009-03-25 04:24 -------- d-----w c:\documents and settings\aseer\Local Settings\Application Data\Google
2009-03-25 03:12 . 2009-03-25 03:12 -------- d-----w c:\windows\Sun
2009-03-25 02:46 . 2009-03-25 02:44 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-23 07:47 . 2009-03-23 07:47 -------- d-----w c:\documents and settings\aseer\Local Settings\Application Data\Adobe
2009-03-18 17:05 . 2008-10-16 11:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-03-18 17:05 . 2008-10-16 11:06 208744 ----a-w c:\windows\system32\muweb.dll
2009-03-18 17:05 . 2008-10-16 11:06 27496 ----a-w c:\windows\system32\mucltui.dll.mui
2009-03-18 10:05 . 2009-04-15 08:36 -------- d-----w c:\documents and settings\aseer\Tracing
2009-03-18 09:03 . 2009-03-18 10:33 -------- d-----w c:\windows\SxsCaPendDel
2009-03-18 02:43 . 2009-02-20 16:50 52224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
2009-03-18 02:43 . 2009-02-20 16:50 459264 -c----w c:\windows\system32\dllcache\msfeeds.dll
2009-03-18 02:43 . 2008-07-09 14:25 1019904 -c----w c:\windows\system32\dllcache\ieframe.dll.mui
2009-03-18 02:43 . 2009-02-20 16:50 268288 -c----w c:\windows\system32\dllcache\iertutil.dll
2009-03-18 02:43 . 2009-02-20 10:20 13824 -c----w c:\windows\system32\dllcache\ieudinit.exe
2009-03-18 02:43 . 2008-07-09 14:25 2455488 -c----w c:\windows\system32\dllcache\ieapfltr.dat
2009-03-18 02:43 . 2009-02-20 16:50 383488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
2009-03-18 02:43 . 2009-02-20 16:50 63488 -c----w c:\windows\system32\dllcache\icardie.dll
2009-03-18 02:43 . 2009-02-20 16:50 6066176 -c----w c:\windows\system32\dllcache\ieframe.dll
2009-03-17 06:54 . 2009-03-17 06:54 -------- d-----w c:\documents and settings\aseer\Application Data\vlc
2009-03-17 00:58 . 2009-04-11 13:55 -------- d-----w c:\documents and settings\aseer\Application Data\uTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-16 00:23 . 2009-03-04 23:32 -------- d-----w c:\documents and settings\aseer\Application Data\DMCache
2009-04-15 08:43 . 2009-04-15 06:35 -------- d-----w c:\program files\TVUPlayer
2009-04-15 08:40 . 2009-03-05 00:19 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-15 08:23 . 2009-04-15 08:23 -------- d-----w c:\program files\Uniblue
2009-04-15 07:57 . 2009-04-15 07:57 2232 ----a-w c:\windows\java\Packages\Data\DBBXN33R.DAT
2009-04-15 07:57 . 2009-04-15 07:57 155995 ----a-w c:\windows\java\Packages\BJ9ZF5JV.ZIP
2009-04-15 07:57 . 2009-04-15 07:57 2678 ----a-w c:\windows\java\Packages\Data\BTJ5JTZL.DAT
2009-04-15 07:57 . 2009-04-15 07:57 2678 ----a-w c:\windows\java\Packages\Data\CLF73N57.DAT
2009-04-15 07:57 . 2009-04-15 07:57 2678 ----a-w c:\windows\java\Packages\Data\NL35FVL3.DAT
2009-04-15 07:57 . 2009-04-15 07:57 2678 ----a-w c:\windows\java\Packages\Data\K9VBNLND.DAT
2009-04-15 07:57 . 2009-04-15 07:57 2678 ----a-w c:\windows\java\Packages\Data\GBLVD3PR.DAT
2009-04-15 07:16 . 2009-04-15 07:13 -------- d-----w c:\program files\Amor SWF to Video Converter
2009-04-15 06:36 . 2009-03-04 22:58 27464 ----a-w c:\documents and settings\aseer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-15 06:00 . 2009-04-15 06:00 -------- d-----w c:\program files\MSConfig CleanUp
2009-04-15 04:47 . 2009-03-04 23:43 -------- d-----w c:\program files\Kaspersky Lab
2009-04-15 04:23 . 2009-04-15 04:21 2227 ----a-w C:\rapport.txt
2009-04-15 03:38 . 2009-04-15 03:36 4662 ----a-w C:\smitfiles.txt
2009-04-14 19:34 . 2009-03-25 04:09 -------- d-----w c:\program files\Google
2009-04-14 15:51 . 2009-04-09 15:57 -------- d-----w c:\program files\Online TV Player 4
2009-04-14 15:40 . 2009-03-17 00:58 -------- d-----w c:\program files\uTorrent
2009-04-14 13:58 . 2001-09-19 17:00 67302 ----a-w c:\windows\system32\perfc001.dat
2009-04-14 13:58 . 2001-09-19 17:00 366678 ----a-w c:\windows\system32\perfh001.dat
2009-04-11 16:51 . 2009-04-11 16:51 -------- d-----w c:\program files\MSBuild
2009-04-11 16:51 . 2009-04-11 16:51 -------- d-----w c:\program files\Reference Assemblies
2009-04-09 19:04 . 2009-03-04 23:32 -------- d-----w c:\program files\Internet Download Manager
2009-04-09 19:02 . 2009-04-09 19:01 -------- d-----w c:\program files\DivX
2009-04-09 19:01 . 2009-04-09 19:01 -------- d-----w c:\program files\Common Files\DivX Shared
2009-04-08 22:11 . 2009-04-08 22:11 -------- d-----w c:\program files\Common Files\xing shared
2009-04-08 22:11 . 2009-04-08 22:11 -------- d-----w c:\program files\Common Files\Real
2009-04-08 22:11 . 2009-03-04 23:24 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-04-08 22:11 . 2009-04-08 22:11 -------- d-----w c:\program files\Real
2009-04-08 21:26 . 2009-04-08 21:26 -------- d-----w c:\program files\Vahab Shalchian
2009-04-08 20:50 . 2009-04-08 20:50 -------- d-----w c:\program files\GRETECH
2009-04-02 07:21 . 2009-04-02 07:21 -------- d-----w c:\program files\Common Files\InstallShield
2009-03-23 07:47 . 2009-03-23 07:47 -------- d-----w c:\program files\Common Files\Adobe
2009-03-23 05:58 . 2009-03-23 05:57 -------- d-----w c:\program files\Windows Live
2009-03-23 05:57 . 2009-03-23 05:57 -------- d-----w c:\program files\Windows Live SkyDrive
2009-03-18 13:31 . 2009-03-04 23:32 -------- d-----w c:\documents and settings\aseer\Application Data\IDM
2009-03-18 10:03 . 2009-03-18 10:03 -------- d-----w c:\program files\Microsoft Sync Framework
2009-03-18 10:01 . 2009-03-18 10:01 -------- d-----w c:\program files\Microsoft
2009-03-18 05:50 . 2009-03-18 05:50 -------- d-----w c:\program files\Common Files\Windows Live
2009-03-07 11:44 . 2009-03-07 11:44 -------- d-----w c:\program files\VideoLAN
2009-03-07 11:30 . 2009-03-07 11:30 -------- d-----w c:\program files\Appwalk.com Sillico Software
2009-03-06 14:20 . 2008-04-14 17:29 283136 ----a-w c:\windows\system32\pdh.dll
2009-03-06 10:24 . 2009-03-04 22:48 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-05 08:37 . 2009-03-05 08:37 -------- d-----w c:\documents and settings\aseer\Application Data\Media Player Classic
2009-03-05 00:20 . 2009-03-05 00:19 -------- d-----w c:\program files\Your Uninstaller 2008
2009-03-05 00:19 . 2009-03-05 00:19 -------- d-----w c:\documents and settings\aseer\Application Data\URSoft
2009-03-04 23:37 . 2009-03-04 23:37 -------- d-----w c:\program files\Windows Media Connect 2
2009-03-04 23:35 . 2009-03-04 23:35 -------- d-----w c:\program files\The KMPlayer
2009-03-04 23:24 . 2009-03-04 23:24 -------- d-----w c:\program files\K-Lite Codec Pack
2009-03-04 23:01 . 2009-03-04 23:01 -------- d-----w c:\program files\CONEXANT
2009-03-04 22:50 . 2009-03-04 22:50 -------- d-----w c:\program files\microsoft frontpage
2009-03-04 22:44 . 2009-03-04 22:44 22144 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-03 00:06 . 2008-04-14 17:29 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-24 19:35 . 2009-04-09 19:02 9464 ------w c:\windows\system32\drivers\cdralw2k.sys
2009-02-24 19:35 . 2009-04-09 19:02 9336 ------w c:\windows\system32\drivers\cdr4_xp.sys
2009-02-24 19:35 . 2009-04-09 19:02 43528 ------w c:\windows\system32\drivers\PxHelp20.sys
2009-02-24 19:35 . 2009-04-09 19:02 129784 ------w c:\windows\system32\pxafs.dll
2009-02-24 19:35 . 2009-04-09 19:02 120056 ------w c:\windows\system32\pxcpyi64.exe
2009-02-24 19:35 . 2009-04-09 19:02 118520 ------w c:\windows\system32\pxinsi64.exe
2009-02-24 19:34 . 2009-02-24 19:34 90112 ----a-w c:\windows\system32\dpl100.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\system32\divx_xx0c.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\system32\divx_xx07.dll
2009-02-24 19:34 . 2009-02-24 19:34 815104 ----a-w c:\windows\system32\divx_xx0a.dll
2009-02-24 19:34 . 2009-02-24 19:34 802816 ----a-w c:\windows\system32\divx_xx11.dll
2009-02-24 19:34 . 2009-02-24 19:34 684032 ----a-w c:\windows\system32\DivX.dll
2009-02-20 16:50 . 2008-04-14 17:29 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-10 16:03 . 2008-04-14 21:12 2067584 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 14:04 . 2008-04-14 17:07 1846656 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:22 . 2008-04-14 17:12 2190592 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:21 . 2008-04-14 17:30 110592 ----a-w c:\windows\system32\services.exe
2009-02-09 10:51 . 2008-04-14 17:29 723456 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:51 . 2008-04-14 17:29 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:51 . 2008-04-14 17:29 681472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:51 . 2008-04-14 17:29 693760 ----a-w c:\windows\system32\ntdll.dll
2009-02-06 15:52 . 2009-02-06 15:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-06 10:39 . 2001-09-19 17:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:57 . 2008-04-14 17:29 56832 ----a-w c:\windows\system32\secur32.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-04-15_03.25.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-16 00:31 . 2009-04-16 00:31 16384 c:\windows\temp\Perflib_Perfdata_154.dat
+ 2009-03-04 23:37 . 2007-11-30 12:39 17784 c:\windows\system32\spmsg.dll
- 2009-03-04 23:37 . 2008-07-09 07:34 17784 c:\windows\system32\spmsg.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 44544 c:\windows\system32\pngfilt.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 44544 c:\windows\system32\pngfilt.dll
+ 2009-04-15 07:57 . 2002-02-18 07:23 21264 c:\windows\system32\msjdbc10.dll
- 2007-08-13 15:54 . 2008-12-20 22:31 52224 c:\windows\system32\msfeedsbs.dll
+ 2007-08-13 15:54 . 2009-02-20 16:50 52224 c:\windows\system32\msfeedsbs.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 27648 c:\windows\system32\jsproxy.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 27648 c:\windows\system32\jsproxy.dll
+ 2009-04-15 07:57 . 2002-02-18 07:23 15120 c:\windows\system32\jdbgmgr.exe
+ 2009-04-15 07:57 . 2002-02-18 07:22 63248 c:\windows\system32\javaprxy.dll
- 2007-08-13 15:39 . 2008-12-19 09:10 13824 c:\windows\system32\ieudinit.exe
+ 2007-08-13 15:39 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe
+ 2008-04-14 17:29 . 2009-02-20 16:50 44544 c:\windows\system32\iernonce.dll
- 2008-04-14 17:29 . 2008-12-20 22:30 44544 c:\windows\system32\iernonce.dll
+ 2008-04-14 17:29 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
- 2008-04-14 17:29 . 2008-12-19 09:08 70656 c:\windows\system32\ie4uinit.exe
- 2007-08-13 15:36 . 2008-12-20 22:30 63488 c:\windows\system32\icardie.dll
+ 2007-08-13 15:36 . 2009-02-20 16:50 63488 c:\windows\system32\icardie.dll
+ 2008-04-14 17:29 . 2009-02-03 19:57 56832 c:\windows\system32\dllcache\secur32.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 44544 c:\windows\system32\dllcache\iernonce.dll
- 2008-04-14 17:29 . 2008-12-20 22:30 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2008-04-14 17:29 . 2009-02-20 10:20 70656 c:\windows\system32\dllcache\ie4uinit.exe
- 2008-04-14 17:29 . 2008-12-19 09:08 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2009-04-15 07:57 . 2002-02-18 07:23 49424 c:\windows\system32\clspack.exe
+ 2009-04-15 07:57 . 2002-02-18 07:23 46352 c:\windows\setdebug.exe
+ 2009-04-15 19:06 . 2008-12-20 22:31 44544 c:\windows\ie7updates\KB963027-IE7\pngfilt.dll
+ 2009-04-15 19:06 . 2008-12-20 22:31 52224 c:\windows\ie7updates\KB963027-IE7\msfeedsbs.dll
+ 2009-04-15 19:06 . 2008-12-20 22:31 27648 c:\windows\ie7updates\KB963027-IE7\jsproxy.dll
+ 2009-04-15 19:06 . 2008-12-19 09:10 13824 c:\windows\ie7updates\KB963027-IE7\ieudinit.exe
+ 2009-04-15 19:06 . 2008-12-20 22:30 44544 c:\windows\ie7updates\KB963027-IE7\iernonce.dll
+ 2009-04-15 19:06 . 2008-04-14 17:29 81920 c:\windows\ie7updates\KB963027-IE7\ieencode.dll
+ 2009-04-15 19:06 . 2008-12-19 09:08 70656 c:\windows\ie7updates\KB963027-IE7\ie4uinit.exe
+ 2009-04-15 19:06 . 2008-12-20 22:30 63488 c:\windows\ie7updates\KB963027-IE7\icardie.dll
+ 2009-04-15 07:57 . 2002-02-18 04:35 6550 c:\windows\jautoexp.dat
+ 2006-10-18 09:32 . 2006-10-18 09:32 807032 c:\windows\system32\wmv9dmod.dll
+ 2009-04-15 07:57 . 2002-02-18 07:23 171792 c:\windows\system32\wjview.exe
- 2008-04-14 17:29 . 2008-12-20 22:31 233472 c:\windows\system32\webcheck.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 233472 c:\windows\system32\webcheck.dll
+ 2009-04-15 07:57 . 2002-02-18 07:23 286992 c:\windows\system32\vmhelper.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 105984 c:\windows\system32\url.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 105984 c:\windows\system32\url.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 102912 c:\windows\system32\occache.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 102912 c:\windows\system32\occache.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 671232 c:\windows\system32\mstime.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 671232 c:\windows\system32\mstime.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 193024 c:\windows\system32\msrating.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 193024 c:\windows\system32\msrating.dll
+ 2009-04-15 07:57 . 2002-02-18 07:23 945936 c:\windows\system32\msjava.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 477696 c:\windows\system32\mshtmled.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 477696 c:\windows\system32\mshtmled.dll
- 2007-08-13 15:54 . 2008-12-20 22:31 459264 c:\windows\system32\msfeeds.dll
+ 2007-08-13 15:54 . 2009-02-20 16:50 459264 c:\windows\system32\msfeeds.dll
+ 2009-04-15 07:57 . 2002-02-18 07:23 154384 c:\windows\system32\msawt.dll
+ 2009-04-15 07:57 . 2002-02-18 07:23 172304 c:\windows\system32\jview.exe
+ 2009-04-15 07:57 . 2002-02-18 07:22 171280 c:\windows\system32\jit.dll
+ 2009-04-15 07:57 . 2002-02-18 07:22 404752 c:\windows\system32\javart.dll
+ 2009-04-15 07:57 . 2002-02-18 07:22 139536 c:\windows\system32\javaee.dll
+ 2009-04-15 07:57 . 2002-02-18 07:22 187152 c:\windows\system32\javacypt.dll
+ 2007-08-13 15:34 . 2009-02-20 16:50 268288 c:\windows\system32\iertutil.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 385024 c:\windows\system32\iedkcs32.dll
- 2007-07-11 09:27 . 2008-12-20 22:30 383488 c:\windows\system32\ieapfltr.dll
+ 2007-07-11 09:27 . 2009-02-20 16:50 383488 c:\windows\system32\ieapfltr.dll
+ 2001-09-19 17:00 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
- 2001-09-19 17:00 . 2008-12-19 05:23 161792 c:\windows\system32\ieakui.dll
- 2008-04-14 17:29 . 2008-12-20 22:30 230400 c:\windows\system32\ieaksie.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 230400 c:\windows\system32\ieaksie.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 153088 c:\windows\system32\ieakeng.dll
- 2008-04-14 17:29 . 2008-12-20 22:30 153088 c:\windows\system32\ieakeng.dll
+ 2002-01-01 00:09 . 2009-04-15 08:09 157160 c:\windows\system32\FNTCACHE.DAT
- 2008-04-14 17:29 . 2008-12-20 22:30 133120 c:\windows\system32\extmgr.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 133120 c:\windows\system32\extmgr.dll
- 2008-04-14 17:29 . 2008-12-20 22:30 214528 c:\windows\system32\dxtrans.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 214528 c:\windows\system32\dxtrans.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 347136 c:\windows\system32\dxtmsft.dll
- 2008-04-14 17:29 . 2008-12-20 22:30 347136 c:\windows\system32\dxtmsft.dll
+ 2009-04-15 07:57 . 2002-02-18 04:34 313856 c:\windows\system32\dx3j.dll
+ 2008-04-14 17:29 . 2009-03-03 00:06 826368 c:\windows\system32\dllcache\wininet.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 826368 c:\windows\system32\dllcache\wininet.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 105984 c:\windows\system32\dllcache\url.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 105984 c:\windows\system32\dllcache\url.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 102912 c:\windows\system32\dllcache\occache.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 102912 c:\windows\system32\dllcache\occache.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 671232 c:\windows\system32\dllcache\mstime.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 671232 c:\windows\system32\dllcache\mstime.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 193024 c:\windows\system32\dllcache\msrating.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 193024 c:\windows\system32\dllcache\msrating.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2009-03-04 22:45 . 2009-02-28 04:54 636072 c:\windows\system32\dllcache\iexplore.exe
+ 2008-04-14 17:29 . 2009-02-20 16:50 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2001-09-19 17:00 . 2009-02-20 05:14 161792 c:\windows\system32\dllcache\ieakui.dll
- 2001-09-19 17:00 . 2008-12-19 05:23 161792 c:\windows\system32\dllcache\ieakui.dll
- 2008-04-14 17:29 . 2008-12-20 22:30 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2008-04-14 17:29 . 2008-12-20 22:30 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2008-04-14 17:29 . 2008-12-20 22:30 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 133120 c:\windows\system32\dllcache\extmgr.dll
- 2008-04-14 17:29 . 2008-12-20 22:30 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2008-04-14 17:29 . 2008-12-20 22:30 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 124928 c:\windows\system32\dllcache\advpack.dll
- 2008-04-14 17:29 . 2008-12-20 22:30 124928 c:\windows\system32\dllcache\advpack.dll
- 2008-04-14 17:29 . 2008-12-20 22:30 124928 c:\windows\system32\advpack.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 124928 c:\windows\system32\advpack.dll
+ 2009-04-15 19:06 . 2008-12-20 22:31 826368 c:\windows\ie7updates\KB963027-IE7\wininet.dll
+ 2009-04-15 19:06 . 2008-12-20 22:31 233472 c:\windows\ie7updates\KB963027-IE7\webcheck.dll
+ 2009-04-15 19:06 . 2008-12-20 22:31 105984 c:\windows\ie7updates\KB963027-IE7\url.dll
+ 2009-04-15 19:06 . 2008-07-09 07:34 380792 c:\windows\ie7updates\KB963027-IE7\spuninst\updspapi.dll
+ 2009-04-15 19:06 . 2008-07-08 12:58 231288 c:\windows\ie7updates\KB963027-IE7\spuninst\spuninst.exe
+ 2009-04-15 19:06 . 2008-12-20 22:31 102912 c:\windows\ie7updates\KB963027-IE7\occache.dll
+ 2009-04-15 19:06 . 2008-12-20 22:31 671232 c:\windows\ie7updates\KB963027-IE7\mstime.dll
+ 2009-04-15 19:06 . 2008-12-20 22:31 193024 c:\windows\ie7updates\KB963027-IE7\msrating.dll
+ 2009-04-15 19:06 . 2008-12-20 22:31 477696 c:\windows\ie7updates\KB963027-IE7\mshtmled.dll
+ 2009-04-15 19:06 . 2008-12-20 22:31 459264 c:\windows\ie7updates\KB963027-IE7\msfeeds.dll
+ 2009-04-15 19:06 . 2008-12-19 05:25 634024 c:\windows\ie7updates\KB963027-IE7\iexplore.exe
+ 2009-04-15 19:06 . 2008-12-20 22:30 267776 c:\windows\ie7updates\KB963027-IE7\iertutil.dll
+ 2009-04-15 19:06 . 2008-12-20 22:30 384512 c:\windows\ie7updates\KB963027-IE7\iedkcs32.dll
+ 2009-04-15 19:06 . 2008-12-20 22:30 383488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dll
+ 2009-04-15 19:06 . 2008-12-19 05:23 161792 c:\windows\ie7updates\KB963027-IE7\ieakui.dll
+ 2009-04-15 19:06 . 2008-12-20 22:30 230400 c:\windows\ie7updates\KB963027-IE7\ieaksie.dll
+ 2009-04-15 19:06 . 2008-12-20 22:30 153088 c:\windows\ie7updates\KB963027-IE7\ieakeng.dll
+ 2009-04-15 19:06 . 2008-12-20 22:30 133120 c:\windows\ie7updates\KB963027-IE7\extmgr.dll
+ 2009-04-15 19:06 . 2008-12-20 22:30 214528 c:\windows\ie7updates\KB963027-IE7\dxtrans.dll
+ 2009-04-15 19:06 . 2008-12-20 22:30 347136 c:\windows\ie7updates\KB963027-IE7\dxtmsft.dll
+ 2009-04-15 19:06 . 2008-12-20 22:30 124928 c:\windows\ie7updates\KB963027-IE7\advpack.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 1160192 c:\windows\system32\urlmon.dll
- 2008-04-14 17:29 . 2008-12-20 22:31 1160192 c:\windows\system32\urlmon.dll
- 2008-04-14 17:29 . 2008-05-07 05:10 1286144 c:\windows\system32\quartz.dll
+ 2008-04-14 17:29 . 2008-12-20 22:13 1286144 c:\windows\system32\quartz.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 3595264 c:\windows\system32\mshtml.dll
+ 2008-04-14 17:29 . 2009-03-21 14:08 1357824 c:\windows\system32\kernel32.dll
- 2008-04-14 17:29 . 2008-04-14 17:29 1357824 c:\windows\system32\kernel32.dll
+ 2007-08-13 15:54 . 2009-02-20 16:50 6066176 c:\windows\system32\ieframe.dll
+ 2007-02-12 13:10 . 2008-07-09 14:25 2455488 c:\windows\system32\ieapfltr.dat
- 2007-02-12 13:10 . 2007-04-17 09:32 2455488 c:\windows\system32\ieapfltr.dat
- 2008-04-14 17:29 . 2008-12-20 22:31 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 1160192 c:\windows\system32\dllcache\urlmon.dll
- 2008-04-14 17:29 . 2008-05-07 05:10 1286144 c:\windows\system32\dllcache\quartz.dll
+ 2008-04-14 17:29 . 2008-12-20 22:13 1286144 c:\windows\system32\dllcache\quartz.dll
+ 2008-04-14 17:29 . 2009-02-20 16:50 3595264 c:\windows\system32\dllcache\mshtml.dll
- 2008-04-14 17:29 . 2008-04-14 17:29 1357824 c:\windows\system32\dllcache\kernel32.dll
+ 2008-04-14 17:29 . 2009-03-21 14:08 1357824 c:\windows\system32\dllcache\kernel32.dll
+ 2009-04-15 19:06 . 2008-12-20 22:31 1160192 c:\windows\ie7updates\KB963027-IE7\urlmon.dll
+ 2009-04-15 19:06 . 2009-01-16 18:01 3594752 c:\windows\ie7updates\KB963027-IE7\mshtml.dll
+ 2009-04-15 19:06 . 2008-12-20 22:30 6066688 c:\windows\ie7updates\KB963027-IE7\ieframe.dll
+ 2009-04-15 19:06 . 2007-04-17 09:32 2455488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"IDMan"="c:\program files\Internet Download Manager\IDM.exe" [2007-07-28 1360304]
"Uniblue RegistryBooster 2009"="c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe" [2008-08-26 2019624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-08 185872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.com.sa/
uInternet Settings,ProxyServer = 169.235.24.232:3127
uInternet Settings,ProxyOverride = local
IE: Download All Links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-16 03:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):58,fe,91,37,20,4b,79,65,62,1d,da,09,2c,de,d9,89,0e,79,d2,30,28,
94,87,c6,b7,51,57,42,68,41,44,b1,f7,66,94,c1,32,65,ba,4a,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{bdc5dc8b-1c14-493c-bf16-05bf5bc27a15}]
@Denied: (Full) (Everyone)
"Model"=dword:00000043
"Therad"=dword:00000018
"MData"=hex(0):cb,9b,ad,ef,27,7d,29,69,f5,02,f0,76,aa,4a,f1,7c,d3,d9,67,7f,6a,
4b,7b,ad,04,7a,b1,b5,76,9b,27,47,ac,a5,96,d6,9d,bd,f2,80,eb,d7,99,c8,96,e8,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3332)
c:\program files\Internet Download Manager\idmmkb.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2009-04-16 3:34 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-16 00:34
ComboFix2.txt 2009-04-15 03:29
Pre-Run: 34,442,207,232 bytes free
Post-Run: 34,440,732,672 bytes free
430 --- E O F --- 2009-04-15 19:07