ComboFix 09-04-19.05 - Alaamery 04/19/2009 19:11.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.447.166 [GMT 3:00]
Running from: c:\documents and settings\Alaamery\My Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-03-19 to 2009-04-19 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-19 16:11 . 2009-04-19 12:57 -------- d-----w c:\documents and settings\Alaamery\Application Data\DMCache
2009-04-19 15:42 . 2009-04-19 15:42 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-19 15:42 . 2009-04-19 15:42 -------- d-----w c:\program files\SUPERAntiSpyware
2009-04-19 15:42 . 2009-04-19 15:42 -------- d-----w c:\documents and settings\Alaamery\Application Data\SUPERAntiSpyware.com
2009-04-19 15:41 . 2009-04-19 15:41 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-19 15:23 . 2009-04-19 15:23 268 ---ha-w C:\sqmdata01.sqm
2009-04-19 15:23 . 2009-04-19 15:23 244 ---ha-w C:\sqmnoopt01.sqm
2009-04-19 14:38 . 2009-04-19 12:49 27664 ----a-w c:\documents and settings\Alaamery\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-19 13:22 . 2009-04-19 13:22 268 ---ha-w C:\sqmdata00.sqm
2009-04-19 13:22 . 2009-04-19 13:22 244 ---ha-w C:\sqmnoopt00.sqm
2009-04-19 13:21 . 2009-04-19 13:21 -------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-04-19 13:07 . 2009-04-19 12:57 -------- d-----w c:\documents and settings\Alaamery\Application Data\IDM
2009-04-19 13:04 . 2009-04-19 13:00 -------- d-----w c:\documents and settings\Alaamery\Application Data\AntiExitPoll
2009-04-19 13:02 . 2009-04-19 13:02 -------- d-----w c:\documents and settings\All Users\Application Data\Axis Readme Second Bat
2009-04-19 13:00 . 2009-04-19 13:00 -------- d-----w c:\program files\AntiExitPoll
2009-04-19 12:59 . 2009-04-19 12:59 -------- d-----w c:\program files\Circle Developement
2009-04-19 12:59 . 2009-04-19 12:59 -------- d-----w c:\program files\Messenger Plus! Live
2009-04-19 12:59 . 2009-04-19 12:58 -------- d-----w c:\program files\Windows Live Messenger Khalid Edition v5.5 Arabic
2009-04-19 12:58 . 2009-04-19 12:58 -------- dc-h--w c:\documents and settings\All Users\Application Data\{6CF41A80-289A-4651-96E0-C4829485C662}
2009-04-19 12:57 . 2009-04-19 12:57 -------- d-----w c:\program files\Internet Download Manager
2009-04-19 12:48 . 2001-09-19 12:00 39982 ----a-w c:\windows\system32\perfc001.dat
2009-04-19 12:48 . 2001-09-19 12:00 251478 ----a-w c:\windows\system32\perfh001.dat
2009-04-19 12:42 . 2009-04-19 12:42 -------- d-----w c:\program files\microsoft frontpage
2009-04-19 12:41 . 2009-04-19 12:41 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-19 12:39 . 2009-04-19 12:39 22144 ----a-w c:\windows\system32\emptyregdb.dat
2009-04-15 09:15 . 2009-04-19 12:53 245760 ----a-r c:\windows\system32\S3Trayp.exe
2009-04-15 09:15 . 2009-04-19 12:53 98304 ----a-r c:\windows\system32\VModes.exe
2009-04-15 09:15 . 2009-04-19 12:53 126976 ----a-r c:\windows\system32\VTTimer.exe
2009-04-15 09:15 . 2009-04-19 12:53 266240 ----a-r c:\windows\system32\S3minset.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 08:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ rmmabez.nt
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\VModes.exe"=
"c:\\WINDOWS\\system32\\VTTimer.exe"=
"c:\\WINDOWS\\system32\\S3trayp.exe"=
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-22 8944]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-22 55024]
S3 abp470n5;abp470n5; [x]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [2008-06-27 332928]
S3 S3GIGP;S3GIGP;c:\windows\system32\DRIVERS\S3gIGPm.sys [2007-03-05 709632]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-22 7408]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - SASDIFSV
*NewlyCreated* - SASENUM
*NewlyCreated* - SASKUTIL
.
Contents of the 'Scheduled Tasks' folder
2009-04-19 c:\windows\Tasks\A98C9BB991930F51.job
- c:\docume~1\alaamery\applic~1\antiex~1\shim size ace.exe [2009-04-19 13:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
FF - ProfilePath - c:\documents and settings\Alaamery\Application Data\Mozilla\Firefox\Profiles\txrzn1p8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sa
FF - component: c:\documents and settings\Alaamery\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-19 19:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-04-19 19:13
ComboFix-quarantined-files.txt 2009-04-19 16:13
Pre-Run: 39,325,134,848 bytes free
Post-Run: 39,402,901,504 bytes free
117