ComboFix 09-05-15.06 - User 05/17/2009 15:27.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.2037.1647 [GMT 3:00]
Running from: c:\documents and settings\User\سطح المكتب\reem\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\LegitCheckControl.dll
c:\windows\system32\x64
d:\recycler\S-1-5-21-2025429265-1275210071-725345543-1003\INFO2
.
---- Previous Run -------
.
c:\windows\IE4 Error Log.txt
.
((((((((((((((((((((((((( Files Created from 2009-04-17 to 2009-05-17 )))))))))))))))))))))))))))))))
.
2009-05-16 23:13 . 2007-08-24 03:03 159744 ----a-r c:\windows\system32\igfxres.dll
2009-05-16 18:07 . 2009-05-16 18:07 -------- d-----w c:\documents and settings\User\Application Data\CyberLink
2009-05-16 16:43 . 2006-03-09 14:57 36972 ------w c:\windows\system32\ActPanel.dll
2009-05-16 16:43 . 2009-05-16 16:43 -------- d-----w c:\program files\JavaSoft
2009-05-16 16:43 . 2009-05-16 16:44 -------- d-----w c:\program files\JAP
2009-05-16 14:47 . 2009-05-17 11:34 -------- d-----w c:\documents and settings\User\Tracing
2009-05-16 14:41 . 2006-11-29 10:06 3426072 ----a-w c:\windows\system32\d3dx9_32.dll
2009-05-16 14:41 . 2009-05-16 14:41 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-05-16 14:40 . 2009-05-16 14:40 -------- d-----w c:\program files\Microsoft
2009-05-16 14:40 . 2009-05-16 14:40 -------- d-----w c:\program files\Windows Live SkyDrive
2009-05-16 14:03 . 2009-05-16 14:03 -------- d-----w c:\program files\Common Files\Windows Live
2009-05-16 14:02 . 2009-05-16 14:02 -------- d-s---w c:\documents and settings\User\UserData
2009-05-16 03:52 . 2009-05-16 03:52 -------- d-----w c:\documents and settings\User\Application Data\Media Player Classic
2009-05-16 03:43 . 2004-08-03 21:55 221184 ----a-w c:\windows\system32\wmpns.dll
2009-05-16 02:39 . 2009-05-16 02:44 -------- d-----w c:\documents and settings\User\Contacts
2009-05-15 15:29 . 2004-08-03 21:55 21504 ----a-w c:\windows\system32\hidserv.dll
2009-05-15 15:29 . 2004-08-03 21:45 14720 ----a-w c:\windows\system32\drivers\kbdhid.sys
2009-05-15 15:29 . 2001-09-18 10:38 12160 ----a-w c:\windows\system32\drivers\mouhid.sys
2009-05-15 15:07 . 2004-08-03 20:08 31616 -c--a-w c:\windows\system32\dllcache\usbccgp.sys
2009-05-15 15:07 . 2004-08-03 20:08 31616 ----a-w c:\windows\system32\drivers\usbccgp.sys
2009-05-15 15:07 . 2001-08-17 11:02 9600 -c--a-w c:\windows\system32\dllcache\hidusb.sys
2009-05-15 15:07 . 2001-08-17 11:02 9600 ----a-w c:\windows\system32\drivers\hidusb.sys
2009-05-13 10:04 . 2009-05-13 10:04 -------- d-----w c:\documents and settings\User\Application Data\ATI
2009-05-13 10:04 . 2009-05-13 10:04 -------- d-----w c:\documents and settings\All Users\Application Data\ATI
2009-05-13 10:04 . 2009-05-13 10:04 -------- d-----w c:\documents and settings\User\Local Settings\Application Data\ATI
2009-05-13 10:04 . 2009-05-13 10:04 0 ----a-w c:\windows\ativpsrm.bin
2009-05-13 09:56 . 2009-05-13 09:56 -------- d-----w c:\program files\Common Files\ATI Technologies
2009-05-13 09:53 . 2008-10-03 14:25 593920 ------w c:\windows\system32\ati2sgag.exe
2009-05-13 09:53 . 2009-05-13 09:56 -------- d-----w c:\program files\ATI Technologies
2009-05-13 09:53 . 2009-05-13 09:53 -------- d-----w C:\ATI
2009-05-13 09:52 . 2004-08-03 20:08 26496 -c--a-w c:\windows\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-17 12:26 . 2001-09-19 12:00 58722 ----a-w c:\windows\system32\perfc001.dat
2009-05-17 12:26 . 2001-09-19 12:00 328418 ----a-w c:\windows\system32\perfh001.dat
2009-05-17 12:18 . 2009-05-07 17:04 -------- d-----w c:\program files\ESET
2009-05-16 23:08 . 2009-05-07 15:29 16608 ----a-w c:\windows\gdrv.sys
2009-05-16 16:43 . 2009-05-07 15:31 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-16 14:46 . 2009-05-07 15:00 95216 ----a-w c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-16 14:41 . 2009-05-07 17:02 -------- d-----w c:\program files\Windows Live
2009-05-16 02:43 . 2009-05-07 17:03 -------- d-----w c:\program files\Messenger Plus! Live
2009-05-07 17:08 . 2009-05-07 17:08 -------- d-----w c:\program files\Nero
2009-05-07 17:08 . 2009-05-07 17:08 -------- d-----w c:\program files\Common Files\Nero
2009-05-07 17:04 . 2009-05-07 17:04 298104 ----a-w c:\windows\system32\imon.dll
2009-05-07 17:04 . 2009-05-07 17:04 512096 ----a-w c:\windows\system32\drivers\amon.sys
2009-05-07 17:04 . 2009-05-07 17:04 15424 ----a-w c:\windows\system32\drivers\nod32drv.sys
2009-05-07 17:02 . 2009-05-07 15:31 -------- d-----w c:\program files\Common Files\InstallShield
2009-05-07 17:00 . 2009-05-07 17:00 -------- d-----w c:\program files\CyberLink
2009-05-07 16:59 . 2009-05-07 16:59 -------- d-----w c:\program files\Common Files\xing shared
2009-05-07 16:59 . 2009-05-07 16:59 -------- d-----w c:\program files\Real
2009-05-07 16:59 . 2009-05-07 16:59 -------- d-----w c:\program files\Common Files\Real
2009-05-07 16:59 . 2009-05-07 16:20 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-05-07 16:59 . 2009-05-07 16:20 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-05-07 16:58 . 2009-05-07 16:58 -------- d-----w c:\program files\mpegable
2009-05-07 16:58 . 2009-05-07 16:58 47104 ------w c:\windows\AKDeInstall.exe
2009-05-07 16:53 . 2009-05-07 16:19 -------- d-----w c:\program files\Common Files\Adobe
2009-05-07 16:20 . 2009-05-07 16:20 -------- d-----w c:\program files\GameHouse
2009-05-07 16:20 . 2009-05-07 16:20 -------- d-----w c:\program files\Zuma Deluxe
2009-05-07 16:20 . 2009-05-07 16:20 -------- d-----w c:\program files\K-Lite Codec Pack
2009-05-07 16:19 . 2009-05-07 16:19 -------- d-----w c:\program files\JetAudio
2009-05-07 16:19 . 2009-05-07 16:19 -------- d-----w c:\program files\GRETECH
2009-05-07 16:18 . 2009-05-07 16:18 -------- d-----w c:\program files\Common Files\ACD Systems
2009-05-07 16:18 . 2009-05-07 16:18 -------- d-----w c:\program files\ACD Systems
2009-05-07 16:18 . 2009-05-07 16:18 10368 ----a-w c:\windows\system32\drivers\pfc.sys
2009-05-07 16:18 . 2009-05-07 16:17 -------- d-----w c:\program files\Java
2009-05-07 16:17 . 2009-05-07 16:17 -------- d-----w c:\program files\Common Files\Java
2009-05-07 16:17 . 2009-05-07 16:17 -------- d-----w c:\program files\Internet Download Manager
2009-05-07 16:17 . 2009-05-07 16:17 -------- d-----w c:\program files\القاموس
2009-05-07 16:17 . 2009-05-07 16:16 -------- d-----w c:\program files\Typing Arabic
2009-05-07 16:16 . 2009-05-07 16:16 -------- d-----w c:\program files\Golden Al-Wafi Translator
2009-05-07 16:04 . 2009-05-07 16:04 -------- d-----w c:\program files\Microsoft.NET
2009-05-07 16:04 . 2009-05-07 16:04 -------- d-----w c:\program files\Microsoft Works
2009-05-07 15:50 . 2009-05-07 15:50 -------- d-----w c:\program files\CONEXANT
2009-05-07 15:34 . 2009-05-07 15:31 -------- d-----w c:\program files\Realtek
2009-05-07 15:31 . 2009-05-07 15:31 315392 ----a-w c:\windows\HideWin.exe
2009-05-07 15:29 . 2009-05-07 15:29 -------- d-----w c:\program files\Intel
2009-05-07 14:41 . 2009-05-07 14:41 -------- d-----w c:\program files\microsoft frontpage
2009-05-07 14:38 . 2009-05-07 14:38 22144 ----a-w c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-07 185896]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-05-18 49152]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-05-07 949376]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-05 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-05 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-05 137752]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-09-19 16844800]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-5-7 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\javaw.exe"=
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2009-05-07 15424]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2008-07-02 89600]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Settings,ProxyServer = 127.0.0.1:4001
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-17 15:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(760)
c:\windows\system32\imon.dll
.
Completion time: 2009-05-17 15:28
ComboFix-quarantined-files.txt 2009-05-17 12:28
Pre-Run: 66,114,224,128 bytes free
Post-Run: 66,102,837,248 bytes free
161