ComboFix 09-05-24.07 - occ 05/25/2009 17:14.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.623.422 [GMT 3:00]
Running from: c:\documents and settings\occ\سطح المكتب\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-04-25 to 2009-05-25 )))))))))))))))))))))))))))))))
.
2009-05-25 13:53 . 2009-05-25 13:53 -------- d-----w c:\documents and settings\occ\Application Data\CyberScrub
2009-05-25 13:19 . 2009-05-25 13:19 -------- d-----w c:\program files\Trend Micro
2009-05-23 05:20 . 2007-02-08 16:46 209152 ----a-w c:\windows\system32\drivers\RTL8187B.sys
2009-05-23 05:17 . 2009-05-23 10:42 96104 ----a-w c:\windows\system32\drivers\avipbb.sys
2009-05-23 05:17 . 2009-02-13 08:29 22360 ----a-w c:\windows\system32\drivers\avgntmgr.sys
2009-05-23 05:17 . 2009-02-13 08:17 45416 ----a-w c:\windows\system32\drivers\avgntdd.sys
2009-05-23 05:17 . 2009-05-23 05:17 -------- d-----w c:\program files\Avira
2009-05-23 05:06 . 2006-04-01 23:33 156672 ----a-r c:\windows\system32\RTLCPAPI.dll
2009-05-23 05:06 . 2006-04-01 23:33 9304064 ----a-r c:\windows\system32\RTLCPL.EXE
2009-05-23 05:06 . 2006-04-01 23:33 77824 ----a-r c:\windows\SOUNDMAN.EXE
2009-05-23 05:06 . 2006-04-01 23:33 2314560 ----a-r c:\windows\system32\drivers\ALCXWDM.SYS
2009-05-21 10:37 . 2009-05-21 10:37 -------- d-----w c:\program files\Common Files\xing shared
2009-05-20 17:13 . 2009-05-20 17:13 -------- d-----w c:\documents and settings\occ\Contacts
2009-05-18 14:04 . 2009-05-21 15:55 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-05-18 12:19 . 2009-05-18 12:19 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-05-18 12:11 . 2009-05-23 10:42 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-18 12:11 . 2009-05-23 05:17 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-25 14:01 . 2001-09-19 18:00 67438 ----a-w c:\windows\system32\perfc001.dat
2009-05-25 14:01 . 2001-09-19 18:00 366874 ----a-w c:\windows\system32\perfh001.dat
2009-05-25 13:52 . 2009-05-25 13:52 -------- d-----w c:\documents and settings\occ\Application Data\cleaner
2009-05-23 09:52 . 2009-05-17 13:28 -------- d-----w c:\documents and settings\All Users\Application Data\Bluetooth
2009-05-23 09:49 . 2009-05-18 01:42 -------- d-----w c:\program files\Atheros
2009-05-21 11:42 . 2009-05-18 00:29 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-21 10:37 . 2009-05-17 15:40 -------- d-----w c:\program files\Common Files\Real
2009-05-18 10:26 . 2009-05-17 13:33 73208 ----a-w c:\documents and settings\occ\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-18 01:42 . 2009-05-18 01:42 17801 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-05-18 01:41 . 2009-05-18 01:41 -------- d-----w c:\program files\Common Files\InstallShield
2009-05-18 00:24 . 2009-05-18 00:24 22144 ----a-w c:\windows\system32\emptyregdb.dat
2009-05-17 20:36 . 2009-05-17 20:36 -------- d-----w c:\program files\Microsoft.NET
2009-05-17 20:21 . 2009-05-17 20:21 -------- d-----w c:\program files\K-Lite Codec Pack
2009-05-17 20:14 . 2009-05-17 20:08 -------- d-----w c:\program files\Common Files\Adobe
2009-05-17 20:08 . 2009-05-18 01:42 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-17 19:43 . 2009-05-17 19:43 0 ----a-w c:\windows\nsreg.dat
2009-05-17 19:19 . 2009-05-17 13:33 -------- d-----w c:\program files\Messenger Plus! Live
2009-05-17 19:19 . 2009-05-17 13:31 -------- d-----w c:\program files\MSN Messenger
2009-05-17 18:24 . 2009-05-17 18:24 -------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-05-17 17:38 . 2009-05-17 17:38 -------- d-----w c:\program files\MSBuild
2009-05-17 17:38 . 2009-05-17 17:38 -------- d-----w c:\program files\Reference Assemblies
2009-05-17 15:49 . 2009-05-17 15:49 390664 ----a-w c:\documents and settings\occ\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-17 15:41 . 2009-05-17 15:40 -------- d-----w c:\program files\Real
2009-05-17 15:40 . 2009-05-17 15:40 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-05-17 15:40 . 2009-05-17 15:40 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-05-17 15:37 . 2009-05-17 15:37 -------- d-----w c:\program files\mpegable
2009-05-17 15:37 . 2009-05-17 15:37 47104 ------w c:\windows\AKDeInstall.exe
2009-05-17 15:33 . 2009-05-17 15:33 2232 ----a-w c:\windows\java\Packages\Data\3N5NLRVN.DAT
2009-05-17 15:33 . 2009-05-17 15:33 155995 ----a-w c:\windows\java\Packages\ELZHVHZ7.ZIP
2009-05-17 15:33 . 2009-05-17 15:33 2678 ----a-w c:\windows\java\Packages\Data\CRZ5NFNZ.DAT
2009-05-17 15:33 . 2009-05-17 15:33 2678 ----a-w c:\windows\java\Packages\Data\GY8DNTVB.DAT
2009-05-17 15:33 . 2009-05-17 15:33 2678 ----a-w c:\windows\java\Packages\Data\SPRVF75Z.DAT
2009-05-17 15:33 . 2009-05-17 15:33 2678 ----a-w c:\windows\java\Packages\Data\OI6086UR.DAT
2009-05-17 15:33 . 2009-05-17 15:33 2678 ----a-w c:\windows\java\Packages\Data\I31JXFPF.DAT
2009-05-17 15:31 . 2009-05-17 15:31 -------- d-----w c:\program files\Java
2009-05-17 15:28 . 2009-05-17 15:28 -------- d-----w c:\documents and settings\All Users\Application Data\GRETECH
2009-05-17 15:27 . 2009-05-17 15:27 -------- d-----w c:\documents and settings\occ\Application Data\GRETECH
2009-05-17 15:27 . 2009-05-17 15:27 -------- d-----w c:\program files\GRETECH
2009-05-17 15:26 . 2009-05-17 15:25 -------- d-----w c:\program files\JetAudio
2009-05-17 15:26 . 2009-05-17 15:25 -------- d-----w c:\program files\Common Files\COWON
2009-05-17 13:33 . 2009-05-17 13:33 -------- d-----w c:\program files\Windows Live
2009-05-17 12:56 . 2009-05-17 12:56 -------- d-----w c:\program files\IVT Corporation
2009-03-08 01:34 . 2008-05-07 05:08 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 01:34 . 2008-05-07 05:08 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 01:33 . 2008-05-07 05:08 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 01:33 . 2008-04-14 21:29 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 01:32 . 2008-05-07 05:08 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 01:32 . 2008-05-07 05:08 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 01:31 . 2008-05-07 05:08 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 01:31 . 2008-05-07 05:08 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 01:31 . 2008-05-07 05:08 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 01:22 . 2008-05-07 05:08 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:20 . 2008-04-14 21:29 283136 ----a-w c:\windows\system32\pdh.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ACU"="c:\program files\Atheros\ACU.exe" [2005-05-31 303104]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-21 198160]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2006-04-01 77824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-5-17 113664]
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-5-17 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil_.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R0 ulsata2;ulsata2;c:\windows\system32\drivers\ulsata2.sys [07/05/2008 08:09 ص 124928]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [23/05/2009 08:17 ص 108289]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [18/05/2009 04:44 ص 194304]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [23/05/2009 08:20 ص 209152]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-25 17:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-796845957-1547161642-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*t*t* \OpenWithList]
@Class="Shell"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(888)
c:\windows\system32\athgina.dll
c:\windows\system32\athcfg11.dll
c:\windows\system32\athcfg11Res.dll
- - - - - - - > 'explorer.exe'(924)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-05-25 17:22
ComboFix-quarantined-files.txt 2009-05-25 14:22
Pre-Run: 14,233,874,432 bytes free
Post-Run: 14,223,945,728 bytes free
161