هذآآ التقريييييير الآووول
ComboFix 09-05-04.A3 - NEW 05/05/2009 21:17.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.238.69 [GMT 3:00]
Running from: c:\documents and settings\NEW\My Documents\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2009-04-05 to 2009-05-05 )))))))))))))))))))))))))))))))
.
2009-05-04 19:04 . 2009-05-04 19:04 -------- d-----w c:\documents and settings\NEW\DoctorWeb
2009-05-03 20:19 . 2009-05-05 18:23 1716256 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-03 20:18 . 2008-07-08 11:54 148496 ----a-w c:\windows\system32\drivers\
00389664.sys
2009-05-03 16:54 . 2009-05-03 20:26 32768 ----a-w c:\documents and settings\tazebama.dll
2009-04-28 15:26 . 2008-10-16 11:06 208744 ----a-w c:\windows\system32\muweb.dll
2009-04-28 15:26 . 2008-10-16 11:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-04-28 14:07 . 2009-04-28 14:07 -------- d-----w c:\windows\BDOSCAN8
2009-04-27 22:52 . 2009-04-27 22:52 -------- d-----w c:\program files\Microsoft Sync Framework
2009-04-27 22:49 . 2006-11-29 10:06 3426072 ----a-w c:\windows\system32\d3dx9_32.dll
2009-04-27 22:47 . 2009-04-27 22:47 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-04-27 22:20 . 2009-04-27 22:20 -------- d-----w c:\program files\Microsoft
2009-04-27 22:19 . 2009-04-27 22:19 -------- d-----w c:\program files\Windows Live SkyDrive
2009-04-27 22:12 . 2008-04-11 19:04 691712 -c----w c:\windows\system32\dllcache\inetcomm.dll
2009-04-27 21:31 . 2008-10-24 11:21 455296 -c----w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-27 21:29 . 2008-06-13 11:05 272128 -c----w c:\windows\system32\dllcache\bthport.sys
2009-04-27 21:28 . 2008-06-12 14:23 91648 -c----w c:\windows\system32\dllcache\mtxoci.dll
2009-04-27 21:28 . 2008-06-12 14:23 161792 -c----w c:\windows\system32\dllcache\msdtcuiu.dll
2009-04-27 21:28 . 2008-06-12 14:23 66560 -c----w c:\windows\system32\dllcache\mtxclu.dll
2009-04-27 21:28 . 2008-06-12 14:23 58880 -c----w c:\windows\system32\dllcache\msdtclog.dll
2009-04-27 21:28 . 2008-06-12 14:23 956928 -c----w c:\windows\system32\dllcache\msdtctm.dll
2009-04-27 21:22 . 2008-06-17 19:02 8461312 -c----w c:\windows\system32\dllcache\shell32.dll
2009-04-27 21:22 . 2008-12-11 10:57 333952 -c----w c:\windows\system32\dllcache\srv.sys
2009-04-27 21:19 . 2009-02-20 08:10 81920 -c----w c:\windows\system32\dllcache\ieencode.dll
2009-04-27 21:19 . 2009-02-20 08:10 619520 -c----w c:\windows\system32\dllcache\urlmon.dll
2009-04-27 21:18 . 2009-02-20 08:10 666112 -c----w c:\windows\system32\dllcache\wininet.dll
2009-04-27 21:18 . 2009-03-02 23:04 1499136 -c----w c:\windows\system32\dllcache\shdocvw.dll
2009-04-27 21:18 . 2009-02-20 08:11 3068416 -c----w c:\windows\system32\dllcache\mshtml.dll
2009-04-27 21:12 . 2008-12-20 22:14 1288192 -c----w c:\windows\system32\dllcache\quartz.dll
2009-04-27 21:11 . 2008-10-15 16:34 337408 -c----w c:\windows\system32\dllcache\netapi32.dll
2009-04-27 20:58 . 2009-02-03 19:59 56832 -c----w c:\windows\system32\dllcache\secur32.dll
2009-04-27 20:58 . 2009-03-21 14:06 989696 -c----w c:\windows\system32\dllcache\kernel32.dll
2009-04-27 20:58 . 2008-06-24 16:43 74240 -c----w c:\windows\system32\dllcache\mscms.dll
2009-04-27 20:54 . 2008-12-05 06:54 144896 -c----w c:\windows\system32\dllcache\schannel.dll
2009-04-27 20:49 . 2008-05-08 14:02 203136 -c----w c:\windows\system32\dllcache\rmcast.sys
2009-04-27 20:47 . 2009-02-09 11:13 1846784 -c----w c:\windows\system32\dllcache\win32k.sys
2009-04-27 20:43 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-27 20:43 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-27 20:40 . 2008-05-09 10:53 90112 -c----w c:\windows\system32\dllcache\wshext.dll
2009-04-27 20:40 . 2008-05-09 10:53 172032 -c----w c:\windows\system32\dllcache\scrrun.dll
2009-04-27 20:40 . 2008-05-09 10:53 180224 -c----w c:\windows\system32\dllcache\scrobj.dll
2009-04-27 20:40 . 2008-05-09 10:53 512000 -c----w c:\windows\system32\dllcache\jscript.dll
2009-04-27 20:40 . 2008-05-09 10:53 430080 -c----w c:\windows\system32\dllcache\vbscript.dll
2009-04-27 20:40 . 2008-05-09 08:45 135168 -c----w c:\windows\system32\dllcache\cscript.exe
2009-04-27 20:40 . 2008-05-08 11:24 155648 -c----w c:\windows\system32\dllcache\wscript.exe
2009-04-27 20:39 . 2008-07-07 20:26 253952 -c----w c:\windows\system32\dllcache\es.dll
2009-04-27 20:34 . 2008-05-01 14:33 331776 -c----w c:\windows\system32\dllcache\msadce.dll
2009-04-27 20:30 . 2008-10-03 10:02 247326 -c----w c:\windows\system32\dllcache\strmdll.dll
2009-04-27 20:30 . 2008-09-04 17:15 1106944 -c----w c:\windows\system32\dllcache\msxml3.dll
2009-04-27 20:29 . 2009-04-27 20:29 -------- d-----w c:\program files\Common Files\Windows Live
2009-04-27 20:20 . 2008-04-14 00:12 221184 ----a-w c:\windows\system32\wmpns.dll
2009-04-27 20:18 . 2009-04-27 20:18 -------- d-----w c:\windows\system32\xircom
2009-04-27 20:18 . 2009-04-27 20:18 -------- d-----w c:\program files\microsoft frontpage
2009-04-27 19:29 . 2009-04-27 19:29 -------- d-----w c:\windows\system32\scripting
2009-04-27 19:29 . 2009-04-27 19:29 -------- d-----w c:\windows\l2schemas
2009-04-27 19:29 . 2009-04-27 19:29 -------- d-----w c:\windows\system32\en
2009-04-27 19:29 . 2009-04-27 19:29 -------- d-----w c:\windows\system32\bits
2009-04-27 19:05 . 2009-04-27 19:37 -------- d-----w c:\windows\ServicePackFiles
2009-04-27 17:58 . 2005-04-12 01:35 63488 ------w c:\windows\system32\drivers\atinxsxx.sys
2009-04-27 15:14 . 2009-04-27 15:14 592 ----a-w c:\windows\chgkey.vbs
2009-04-27 15:10 . 2009-04-27 15:10 -------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-04-27 14:49 . 2008-07-09 07:38 26488 ----a-w c:\windows\system32\spupdsvc.exe
2009-04-27 14:49 . 2009-05-05 16:44 -------- d--h--w c:\windows\$hf_mig$
2009-04-27 14:34 . 2008-10-16 11:09 43544 ----a-w c:\windows\system32\wups2.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-05 18:23 . 2009-05-03 20:19 16304 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-04 20:13 . 2008-10-20 15:43 -------- d-----w c:\program files\Circle Developement
2009-05-04 17:50 . 2008-09-01 20:43 -------- d-----w c:\program files\Real_SC
2009-05-03 23:32 . 2009-05-03 16:44 769024 ----a-w c:\windows\pchealth\helpctr\binaries\OLDA.tmp
2009-05-03 16:37 . 2008-09-01 19:00 169984 ----a-w c:\windows\pchealth\helpctr\binaries\msconfig.exe
2009-04-27 23:19 . 2008-10-20 15:43 -------- d-----w c:\program files\Windows Live
2009-04-27 20:28 . 2008-09-01 20:37 84752 ----a-w c:\documents and settings\NEW\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-27 19:47 . 2008-09-01 19:05 166455 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-21 16:26 . 2008-10-15 17:13 -------- d-----w c:\program files\MSN Messenger
2009-03-14 13:40 . 2008-09-12 04:00 -------- d-----w c:\program files\Google
2009-03-09 18:39 . 2009-03-09 18:39 -------- d-----w c:\program files\Common Files\xing shared
2009-03-09 18:38 . 2008-09-01 20:25 -------- d-----w c:\program files\Common Files\Real
2009-03-09 18:35 . 2008-09-01 20:25 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-03-06 14:22 . 2001-08-23 09:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-02-26 00:01 . 2009-02-26 00:01 0 ----a-w c:\windows\nsreg.dat
2009-02-20 08:10 . 2001-08-23 09:00 666112 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2001-08-23 09:00 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2001-08-23 09:00 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2001-08-23 09:00 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2001-08-23 09:00 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2001-08-23 09:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2001-08-23 09:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-07 16:02 . 2005-04-12 04:30 2066048 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 16:43 . 2009-02-06 16:43 307576 ----a-w c:\windows\WLXPGSS.SCR
2009-02-06 15:52 . 2009-02-06 15:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-06 11:11 . 2001-08-23 09:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2001-08-23 09:00 2189056 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2001-08-23 09:00 35328 ----a-w c:\windows\system32\sc.exe
2006-10-11 08:04 . 2009-02-25 23:56 61036 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2006-10-11 08:04 . 2009-02-25 23:56 48742 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2006-10-11 08:05 . 2009-02-25 23:56 29313 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2006-10-11 08:05 . 2009-02-25 23:56 41082 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2006-10-11 08:04 . 2009-02-25 23:56 166510 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-05-03_18.53.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-08-23 09:00 . 2008-05-09 10:53 90112 c:\windows\system32\wshext.dll
- 2001-08-23 09:00 . 2008-04-14 00:12 90112 c:\windows\system32\wshext.dll
+ 2008-04-14 00:12 . 2008-10-23 10:06 62976 c:\windows\system32\tzchange.exe
- 2009-04-27 14:48 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
+ 2009-04-27 14:48 . 2007-11-30 11:18 17272 c:\windows\system32\spmsg.dll
+ 2001-08-23 09:00 . 2009-02-03 19:59 56832 c:\windows\system32\secur32.dll
- 2001-08-23 09:00 . 2009-05-02 18:47 59774 c:\windows\system32\perfc009.dat
+ 2001-08-23 09:00 . 2009-05-05 17:02 59774 c:\windows\system32\perfc009.dat
- 2008-09-01 18:54 . 2008-04-14 00:12 91648 c:\windows\system32\mtxoci.dll
+ 2008-09-01 18:54 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll
- 2001-08-23 09:00 . 2008-04-14 00:12 66560 c:\windows\system32\mtxclu.dll
+ 2001-08-23 09:00 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll
+ 2008-09-01 18:54 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll
- 2008-09-01 18:54 . 2008-04-14 00:11 58880 c:\windows\system32\msdtclog.dll
+ 2001-08-23 09:00 . 2008-06-24 16:43 74240 c:\windows\system32\mscms.dll
+ 2009-05-04 21:50 . 2009-02-06 10:39 35328 c:\windows\system32\dllcache\sc.exe
+ 2008-12-01 07:30 . 2009-05-05 16:35 35088 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-12-01 07:30 . 2008-12-01 07:30 35088 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-12-01 07:30 . 2009-05-05 16:35 18704 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-12-01 07:30 . 2008-12-01 07:30 18704 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-12-01 07:30 . 2008-12-01 07:30 20240 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-12-01 07:30 . 2009-05-05 16:35 20240 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-05-03 21:29 . 2009-05-03 21:29 17920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\24d8a3cdd8496e48aa7536490a99b980\Microsoft.VisualC.ni.dll
+ 2009-05-03 22:13 . 2009-05-03 22:13 81920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\d3673b81f94b4548815a95b94e756ebe\Microsoft.Build.Framework.ni.dll
+ 2009-05-03 21:33 . 2009-05-03 21:33 15360 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\455c2dac876b144cb597de1579eef94d\dfsvc.ni.exe
- 2001-08-23 09:00 . 2008-04-14 00:12 155648 c:\windows\system32\wscript.exe
+ 2001-08-23 09:00 . 2008-05-08 11:24 155648 c:\windows\system32\wscript.exe
+ 2001-08-23 09:00 . 2008-12-16 12:30 354304 c:\windows\system32\winhttp.dll
- 2001-08-23 09:00 . 2008-04-14 00:12 354304 c:\windows\system32\winhttp.dll
+ 2009-03-10 19:18 . 2009-03-10 19:18 934792 c:\windows\system32\WgaTray.exe
+ 2009-03-10 19:18 . 2009-03-10 19:18 239496 c:\windows\system32\WgaLogon.dll
+ 2008-09-01 18:54 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2008-09-01 18:54 . 2009-02-09 12:10 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2008-09-01 18:54 . 2009-02-09 12:10 473600 c:\windows\system32\wbem\fastprox.dll
+ 2001-08-23 09:00 . 2008-05-09 10:53 430080 c:\windows\system32\vbscript.dll
+ 2001-08-23 09:00 . 2009-02-20 08:10 619520 c:\windows\system32\urlmon.dll
- 2001-08-23 09:00 . 2008-04-14 00:12 619520 c:\windows\system32\urlmon.dll
+ 2001-08-23 09:00 . 2008-10-03 10:02 247326 c:\windows\system32\strmdll.dll
+ 2001-08-23 09:00 . 2008-05-09 10:53 172032 c:\windows\system32\scrrun.dll
- 2001-08-23 09:00 . 2008-04-14 00:12 172032 c:\windows\system32\scrrun.dll
+ 2001-08-23 09:00 . 2008-05-09 10:53 180224 c:\windows\system32\scrobj.dll
- 2001-08-23 09:00 . 2008-04-14 00:12 180224 c:\windows\system32\scrobj.dll
+ 2001-08-23 09:00 . 2008-12-05 06:54 144896 c:\windows\system32\schannel.dll
+ 2001-08-23 09:00 . 2009-05-05 17:02 395534 c:\windows\system32\perfh009.dat
- 2001-08-23 09:00 . 2009-05-02 18:47 395534 c:\windows\system32\perfh009.dat
- 2001-08-23 09:00 . 2008-04-14 00:12 337408 c:\windows\system32\netapi32.dll
+ 2001-08-23 09:00 . 2008-10-15 16:34 337408 c:\windows\system32\netapi32.dll
+ 2001-08-23 09:00 . 2008-06-20 17:46 245248 c:\windows\system32\mswsock.dll
- 2001-08-23 09:00 . 2008-04-14 00:12 245248 c:\windows\system32\mswsock.dll
+ 2008-09-01 18:54 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll
- 2008-09-01 18:54 . 2008-04-14 00:11 161792 c:\windows\system32\msdtcuiu.dll
- 2008-09-01 18:54 . 2008-04-14 00:11 956928 c:\windows\system32\msdtctm.dll
+ 2008-09-01 18:54 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll
+ 2008-09-01 18:54 . 2008-06-12 16:53 428032 c:\windows\system32\msdtcprx.dll
+ 2001-08-23 09:00 . 2009-03-21 14:06 989696 c:\windows\system32\kernel32.dll
- 2001-08-23 09:00 . 2008-04-14 00:11 989696 c:\windows\system32\kernel32.dll
- 2001-08-23 09:00 . 2008-04-14 00:11 512000 c:\windows\system32\jscript.dll
+ 2001-08-23 09:00 . 2008-05-09 10:53 512000 c:\windows\system32\jscript.dll
- 2008-09-01 18:59 . 2008-04-14 00:11 691712 c:\windows\system32\inetcomm.dll
+ 2008-09-01 18:59 . 2008-04-11 19:04 691712 c:\windows\system32\inetcomm.dll
+ 2001-08-23 09:00 . 2008-10-23 12:36 286720 c:\windows\system32\gdi32.dll
+ 2008-09-01 21:44 . 2009-05-05 16:55 298848 c:\windows\system32\FNTCACHE.DAT
- 2008-09-01 21:44 . 2009-04-27 20:16 298848 c:\windows\system32\FNTCACHE.DAT
+ 2001-08-23 09:00 . 2008-07-07 20:26 253952 c:\windows\system32\es.dll
+ 2001-08-23 09:00 . 2008-06-20 11:08 225856 c:\windows\system32\drivers\tcpip6.sys
+ 2001-08-23 09:00 . 2008-06-20 11:51 361600 c:\windows\system32\drivers\tcpip.sys
+ 2001-08-23 09:00 . 2008-12-11 10:57 333952 c:\windows\system32\drivers\srv.sys
+ 2001-08-23 09:00 . 2008-05-08 14:02 203136 c:\windows\system32\drivers\rmcast.sys
+ 2001-08-23 09:00 . 2008-10-24 11:21 455296 c:\windows\system32\drivers\mrxsmb.sys
+ 2008-09-02 20:55 . 2008-06-13 11:05 272128 c:\windows\system32\drivers\bthport.sys
+ 2001-08-23 09:00 . 2008-08-14 10:04 138496 c:\windows\system32\drivers\afd.sys
- 2001-08-23 09:00 . 2008-04-14 00:11 147968 c:\windows\system32\dnsapi.dll
+ 2001-08-23 09:00 . 2008-06-20 17:46 147968 c:\windows\system32\dnsapi.dll
+ 2009-05-04 21:50 . 2009-02-06 10:10 227840 c:\windows\system32\dllcache\wmiprvse.exe
+ 2009-05-04 21:50 . 2009-02-09 12:10 453120 c:\windows\system32\dllcache\wmiprvsd.dll
+ 2008-12-16 12:30 . 2008-12-16 12:30 354304 c:\windows\system32\dllcache\winhttp.dll
+ 2009-03-10 19:18 . 2009-03-10 19:18 934792 c:\windows\system32\dllcache\WgaTray.exe
+ 2009-03-10 19:18 . 2009-03-10 19:18 239496 c:\windows\system32\dllcache\wgaLogon.dll
+ 2008-06-20 11:08 . 2008-06-20 11:08 225856 c:\windows\system32\dllcache\tcpip6.sys
+ 2008-06-20 11:51 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\tcpip.sys
+ 2009-05-04 21:50 . 2009-02-06 11:11 110592 c:\windows\system32\dllcache\services.exe
+ 2009-05-04 21:50 . 2009-02-09 12:10 401408 c:\windows\system32\dllcache\rpcss.dll
+ 2009-05-04 21:50 . 2009-03-06 14:22 284160 c:\windows\system32\dllcache\pdh.dll
+ 2009-05-04 21:50 . 2009-02-09 12:10 714752 c:\windows\system32\dllcache\ntdll.dll
+ 2008-06-20 17:46 . 2008-06-20 17:46 245248 c:\windows\system32\dllcache\mswsock.dll
+ 2008-06-12 16:53 . 2008-06-12 16:53 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2009-05-04 21:50 . 2009-02-09 12:10 729088 c:\windows\system32\dllcache\lsasrv.dll
+ 2008-10-23 12:36 . 2008-10-23 12:36 286720 c:\windows\system32\dllcache\gdi32.dll
+ 2009-05-04 21:50 . 2009-02-09 12:10 473600 c:\windows\system32\dllcache\fastprox.dll
+ 2008-06-20 17:46 . 2008-06-20 17:46 147968 c:\windows\system32\dllcache\dnsapi.dll
+ 2008-06-20 11:40 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys
+ 2009-05-04 21:50 . 2009-02-09 12:10 617472 c:\windows\system32\dllcache\advapi32.dll
+ 2001-08-23 09:00 . 2008-05-09 08:45 135168 c:\windows\system32\cscript.exe
+ 2008-04-13 18:53 . 2009-05-03 20:54 640000 c:\windows\network diagnostic\xpnetdiag.exe
- 2008-12-01 07:30 . 2008-12-01 07:30 888080 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-12-01 07:30 . 2009-05-05 16:35 888080 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-12-01 07:30 . 2008-12-01 07:30 272648 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-12-01 07:30 . 2009-05-05 16:35 272648 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-12-01 07:30 . 2009-05-05 16:35 922384 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2008-12-01 07:30 . 2008-12-01 07:30 922384 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-12-01 07:30 . 2009-05-05 16:35 845584 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2008-12-01 07:30 . 2008-12-01 07:30 845584 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2008-12-01 07:30 . 2008-12-01 07:30 217864 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2008-12-01 07:30 . 2009-05-05 16:35 217864 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2008-12-01 07:30 . 2008-12-01 07:30 184080 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-12-01 07:30 . 2009-05-05 16:35 184080 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-12-01 07:30 . 2009-05-05 16:35 159504 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2008-12-01 07:30 . 2008-12-01 07:30 159504 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-05-05 16:30 . 2009-05-05 16:30 135168 c:\windows\Installer\{901E0401-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-09-01 20:22 . 2008-09-01 20:22 135168 c:\windows\Installer\{901E0401-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-04-27 21:31 . 2008-10-24 11:21 455296 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2009-04-27 21:29 . 2008-06-13 11:05 272128 c:\windows\Driver Cache\i386\bthport.sys
+ 2009-05-03 21:33 . 2009-05-03 21:33 638976 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\c88a25685864dc46aa791d91a18330ad\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2009-05-03 21:31 . 2009-05-03 21:31 143360 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\fe2dceb4d27487439297791c933b8394\WindowsLive.Writer.Extensibility.ni.dll
+ 2009-05-03 21:32 . 2009-05-03 21:32 929792 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\eabf6538bae6ac40baf2e00490b556dd\WindowsLive.Writer.BlogClient.ni.dll
+ 2009-05-03 21:33 . 2009-05-03 21:33 376832 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c4f2b3f5d6d7504c815a23f6622d4bfe\WindowsLive.Writer.SpellChecker.ni.dll
+ 2009-05-03 21:27 . 2009-05-03 21:27 352256 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ad9c87974c8f9d4ba419aa29357007a6\WindowsLive.Writer.Interop.SHDocVw.ni.dll
+ 2009-05-03 21:27 . 2009-05-03 21:27 176128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a356db1b551f474eb686f7e99151133c\WindowsLive.Writer.HtmlParser.ni.dll
+ 2009-05-03 21:33 . 2009-05-03 21:33 163840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\66388011e2821c4cb45b6569bfdbd895\WindowsLive.Writer.Instrumentation.ni.dll
+ 2009-05-03 21:33 . 2009-05-03 21:33 643072 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\6499e935b754a84b897b9afe153021ab\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2009-05-03 21:31 . 2009-05-03 21:31 135168 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\63d1171faac2434a9cac9fb5900114ae\WindowsLive.Writer.Passport.ni.dll
+ 2009-05-03 21:33 . 2009-05-03 21:33 139264 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\59868c2cba9afb43bc5839373dc9c8b0\WindowsLive.Writer.FileDestinations.ni.dll
+ 2009-05-03 21:32 . 2009-05-03 21:32 114688 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\4d03e2be413af94a906ad84ffc78bbfa\WindowsLive.Writer.Api.ni.dll
+ 2009-05-03 21:31 . 2009-05-03 21:31 475136 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\2875363de6031d448a9bfbf4e328902b\WindowsLive.Writer.Localization.ni.dll
+ 2009-05-03 21:27 . 2009-05-03 21:27 335872 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1a3766278131c249bc57350a54989136\WindowsLive.Writer.Interop.Mshtml.ni.dll
+ 2009-05-03 21:26 . 2009-05-03 21:26 335872 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\10191e7cc0cc6943b3c22efa9c770084\WindowsLive.Writer.Interop.ni.dll
+ 2009-05-03 21:31 . 2009-05-03 21:31 286720 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\
0fe3b867bfbbf740a39d6b5a4e110acc\WindowsLive.Writer.Mshtml.ni.dll
+ 2009-05-03 21:26 . 2009-05-03 21:26 204800 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\
04d822f39e38874cb7885fabbe538e67\WindowsLive.Writer.BrowserControl.ni.dll
+ 2009-05-03 21:32 . 2009-05-03 21:32 163840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\51c4a38066787943830daa3fc732ba5f\WindowsLive.Client.ni.dll
+ 2009-05-03 21:30 . 2009-05-03 21:30 237568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\50f5b9039b890647b3dbdabd59d4685a\System.Web.RegularExpressions.ni.dll
+ 2009-05-03 21:30 . 2009-05-03 21:30 684032 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\153bc315968c774db23c5d8f6f33fb77\System.Transactions.ni.dll
+ 2009-05-03 21:30 . 2009-05-03 21:30 233472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e4ca591de2d862499d9a098c4befc0c2\System.ServiceProcess.ni.dll
+ 2009-05-03 21:30 . 2009-05-03 21:30 815104 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\365f4ba2aa7a0c4181e0972dc7e69cad\System.Runtime.Remoting.ni.dll
+ 2009-05-03 21:30 . 2009-05-03 21:30 294912 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\ede0e885a45578498240afe2d461110f\System.EnterpriseServices.Wrapper.dll
+ 2009-05-03 21:30 . 2009-05-03 21:30 659456 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\ede0e885a45578498240afe2d461110f\System.EnterpriseServices.ni.dll
+ 2009-05-03 21:30 . 2009-05-03 21:30 512000 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\6580c2b988187a49a25ee207d0b8beef\System.DirectoryServices.Protocols.ni.dll
+ 2009-05-03 21:30 . 2009-05-03 21:30 167936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\4db9246c32665f478c1b530456c88444\System.Configuration.Install.ni.dll
+ 2009-05-03 22:13 . 2009-05-03 22:13 163840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\884ad0a3a5b33e4f84e7dde6fd480f78\Microsoft.Build.Utilities.ni.dll
+ 2009-05-03 22:13 . 2009-05-03 22:13 880640 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\a5c4b89e6c371740880a4ce6d7f64d9e\Microsoft.Build.Engine.ni.dll
+ 2009-05-03 21:33 . 2009-05-03 21:33 237568 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\64977a25c80b2f4fb00073af729a80f6\CustomMarshalers.ni.dll
+ 2009-04-27 21:11 . 2008-04-15 17:47 1724416 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\GdiPlus.dll
+ 2001-08-23 09:00 . 2008-06-17 19:02 8461312 c:\windows\system32\shell32.dll
- 2001-08-23 09:00 . 2008-04-14 00:12 8461312 c:\windows\system32\shell32.dll
+ 2001-08-23 09:00 . 2009-03-02 23:04 1499136 c:\windows\system32\shdocvw.dll
- 2001-08-23 09:00 . 2008-04-14 00:12 1499136 c:\windows\system32\shdocvw.dll
- 2001-08-23 09:00 . 2008-04-14 00:12 1288192 c:\windows\system32\quartz.dll
+ 2001-08-23 09:00 . 2008-12-20 22:14 1288192 c:\windows\system32\quartz.dll
+ 2008-04-14 00:12 . 2008-09-10 01:14 1307648 c:\windows\system32\msxml6.dll
+ 2001-08-23 09:00 . 2008-09-04 17:15 1106944 c:\windows\system32\msxml3.dll
+ 2001-08-23 09:00 . 2009-02-20 08:11 3068416 c:\windows\system32\mshtml.dll
+ 2008-03-20 15:06 . 2009-03-10 19:18 1482112 c:\windows\system32\LegitCheckControl.dll
+ 2009-05-04 21:50 . 2009-02-06 11:08 2189056 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2009-05-04 21:50 . 2009-02-06 10:32 2023936 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-02-07 16:02 . 2009-02-07 16:02 2066048 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2009-05-04 21:50 . 2009-02-06 11:06 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-09-10 01:14 . 2008-09-10 01:14 1307648 c:\windows\system32\dllcache\msxml6.dll
+ 2008-12-01 07:30 . 2009-05-05 16:35 1172240 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-12-01 07:30 . 2008-12-01 07:30 1172240 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-12-01 07:30 . 2008-12-01 07:30 1165584 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-12-01 07:30 . 2009-05-05 16:35 1165584 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2006-09-15 13:25 . 2006-09-15 13:25 3611416 c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.4518\OUTLFLTR.DAT
+ 2009-05-04 21:50 . 2009-02-06 11:08 2189056 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2009-05-04 21:50 . 2009-02-06 10:32 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-02-07 16:02 . 2009-02-07 16:02 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-05-04 21:50 . 2009-02-06 11:06 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-05-03 21:31 . 2009-05-03 21:31 1163264 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8ee490deea031d40b0748dec396d1f0e\WindowsLive.Writer.ApplicationFramework.ni.dll
+ 2009-05-03 21:26 . 2009-05-03 21:26 2260992 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\63c09169854eb045977cb0251eeaab86\WindowsLive.Writer.CoreServices.ni.dll
+ 2009-05-03 21:30 . 2009-05-03 21:30 1945600 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\563bd7fdcaa8b040a8c50b77a0f4632d\System.Web.Services.ni.dll
+ 2009-05-03 22:14 . 2009-05-03 22:14 2310144 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\3e90191c3493364b805f5f51358223b6\System.Web.Mobile.ni.dll
+ 2009-05-03 21:30 . 2009-05-03 21:30 1220608 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\241af64508a73848ab0d648b6c0499b4\System.DirectoryServices.ni.dll
+ 2009-05-03 21:30 . 2009-05-03 21:30 1183744 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\5abf3367b29e3e499c21c8eb5de8b1e8\System.Data.OracleClient.ni.dll
+ 2009-05-03 22:14 . 2009-05-03 22:14 1724416 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\
0b2b224681d9574b8d4c38735c25c14b\Microsoft.VisualBasic.ni.dll
+ 2009-05-03 22:13 . 2009-05-03 22:13 1691648 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\c836be84d3834b4d9ddc977ef061ec62\Microsoft.Build.Tasks.ni.dll
+ 2009-05-03 21:29 . 2009-05-03 21:29 11808768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\8feac24b569cb449886bac0ef6dd3c68\System.Web.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-12 68856]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-05-03 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2009-05-03 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-01 98304]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-09 185896]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-9-1 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= c:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe
"c:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
R1 is-6NGI7drv;is-6NGI7drv;c:\windows\system32\drivers\
00389664.sys [5/3/2009 11:18 PM 148496]
R1 SMBHC;Microsoft SM Bus Host Controller Driver;c:\windows\system32\drivers\smbhc.sys [9/2/2008 12:51 AM 6784]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [1/14/2009 5:53 PM 226656]
R3 SMBBATT;Microsoft Smart Battery Driver;c:\windows\system32\drivers\smbbatt.sys [9/2/2008 12:51 AM 16000]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3798491e-fccb-11dd-87eb-000e35e7f4b1}]
\Shell\AutoRun\command - F:\zPharaoh.exe
\Shell\explore\command - F:\zPharaoh.exe
\Shell\open\command - F:\zPharaoh.exe
.
.
------- Supplementary Scan -------
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-05 21:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
Completion time: 2009-05-05 21:33 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-05 18:33
ComboFix2.txt 2009-05-03 19:02
Pre-Run: 15,111,028,736 bytes free
Post-Run: 15,239,647,232 bytes free
374 --- E O F --- 2009-05-05 16:45