ComboFix 09-06-16.01 - ع ــزيز درملي 06/17/2009 0:09.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.446.96 [GMT 3:00]
Running from: D:\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\ع ــزيز درملي\Application Data\tazebama
C:\autorun.inf
c:\documents and settings\ع ــزيز درملي\Application Data\tazebama\tazebama.log
c:\documents and settings\ع ــزيز درملي\Application Data\tazebama\zPharaoh.dat
c:\windows\IE4 Error Log.txt
c:\windows\system32\kakle.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-05-16 to 2009-06-16 )))))))))))))))))))))))))))))))
.
2009-06-16 16:19 . 2009-06-16 16:19 -------- d-----w- C:\AppServ
2009-06-16 01:20 . 2009-06-16 01:20 390664 ----a-w- c:\documents and settings\mohammad\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-16 01:13 . 2009-06-16 01:13 -------- d-----w- c:\program files\Common Files\xing shared
2009-06-15 22:01 . 2009-06-15 22:01 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-06-15 10:39 . 2009-06-15 10:39 -------- d-----w- c:\documents and settings\ع ــزيز درملي\Local Settings\Application Data\Real
2009-06-15 10:33 . 2009-06-15 10:33 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-06-14 23:44 . 2009-06-14 23:44 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-06-14 23:44 . 2009-06-14 23:44 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-06-14 08:48 . 2009-06-14 08:48 -------- d-sh--w- C:\FOUND.051
2009-06-13 15:58 . 2008-07-08 11:54 148496 ----a-w- c:\windows\system32\drivers\37872614.sys
2009-06-13 12:37 . 2009-06-13 12:37 -------- d-sh--w- C:\FOUND.050
2009-06-12 19:00 . 2009-06-16 03:33 32 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-12 18:59 . 2008-07-08 11:54 148496 ----a-w- c:\windows\system32\drivers\70448432.sys
2009-06-12 17:23 . 2009-06-12 17:23 -------- d-----w- c:\program files\aod
2009-06-12 17:23 . 2009-06-12 17:23 -------- d-----w- c:\program files\Common Files\Real
2009-06-11 10:03 . 2009-04-30 21:13 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-06-11 10:03 . 2009-04-30 21:13 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-10 22:03 . 2009-06-10 22:03 -------- d-sh--w- C:\FOUND.049
2009-06-10 18:31 . 2009-06-10 18:31 152576 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-10 01:21 . 2009-06-10 01:21 34304 ----a-w- c:\documents and settings\mohammad\Application Data\Thinstall\Microsoft Office FrontPage 2003\4000009c00002i\IEXPLORE.EXE
2009-06-09 11:53 . 2009-06-09 11:53 34304 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\Thinstall\Microsoft Office FrontPage 2003\10000001200002i\msimn.exe
2009-06-09 11:51 . 2009-06-09 11:51 34304 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\Thinstall\Microsoft Office FrontPage 2003\4000001300002i\GoogleToolbarNotifier.exe
2009-06-09 11:51 . 2009-06-09 11:51 34304 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\Thinstall\Microsoft Office FrontPage 2003\4000008100002i\realplay.exe
2009-06-09 11:51 . 2009-06-09 11:51 34304 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\Thinstall\Microsoft Office FrontPage 2003\4000009c00002i\IEXPLORE.EXE
2009-06-08 20:43 . 2009-06-08 20:43 -------- d-----w- c:\documents and settings\ع ــزيز درملي\Application Data\Thinstall
2009-06-08 20:20 . 2009-06-08 20:20 -------- d-----w- c:\documents and settings\mohammad\Application Data\Thinstall
2009-06-07 11:53 . 2009-06-07 11:53 -------- d-----w- c:\documents and settings\All Users\Application Data\SPAUN IT
2009-06-07 11:52 . 2009-06-07 11:53 -------- d-----w- c:\documents and settings\All Users\Application Data\{81A39259-3FF0-430A-95F5-EF566D08DE70}
2009-06-07 11:52 . 2009-01-13 08:49 575060 ----a-w- c:\documents and settings\All Users\Application Data\{81A39259-3FF0-430A-95F5-EF566D08DE70}\mia.dll
2009-06-07 11:52 . 2009-06-07 11:52 -------- d-----w- c:\program files\SPAUN
2009-06-05 12:30 . 2009-06-05 12:30 -------- d-sh--w- C:\FOUND.048
2009-06-04 15:22 . 2009-06-04 15:22 720896 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\PlusBrowse\lymuvbdp.exe
2009-06-04 15:21 . 2009-06-04 15:21 -------- d-----w- c:\program files\PlusBrowse
2009-06-03 22:16 . 2009-06-11 19:13 918383 ----a-w- c:\documents and settings\All Users\Application Data\Cast ping base frag\Amen Settings.exe
2009-06-03 22:16 . 2009-06-11 21:53 918383 ----a-w- c:\documents and settings\mohammad\Application Data\PlusBrowse\gzrpzkir.exe
2009-06-03 15:25 . 2009-06-03 15:25 -------- d-sh--w- C:\FOUND.047
2009-06-02 15:00 . 2009-06-02 15:00 724992 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\PlusBrowse\iwfrhphc.exe
2009-06-02 14:35 . 2009-06-02 14:35 -------- d-sh--w- C:\FOUND.046
2009-06-01 21:11 . 2009-06-01 21:11 -------- d-sh--w- C:\FOUND.045
2009-05-31 18:37 . 2009-05-31 18:37 -------- d-----w- c:\windows\system32\NtmsData
2009-05-31 10:17 . 2009-05-31 10:17 -------- d-sh--w- C:\FOUND.044
2009-05-31 05:14 . 2009-06-11 21:53 516975 ----a-w- c:\documents and settings\mohammad\Application Data\PlusBrowse\yzkcvswm.exe
2009-05-27 08:57 . 2009-05-27 08:57 -------- d-sh--w- C:\FOUND.043
2009-05-23 09:50 . 2009-05-23 09:50 782336 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\PlusBrowse\qcyximgp.exe
2009-05-23 09:40 . 2009-05-23 09:40 -------- d-sh--w- C:\FOUND.042
2009-05-23 02:09 . 2009-06-11 21:53 975727 ----a-w- c:\documents and settings\mohammad\Application Data\PlusBrowse\vaxbysyh.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 03:33 . 2009-06-12 19:00 32 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-13 12:21 . 2001-09-19 08:00 70900 ----a-w- c:\windows\system32\perfc001.dat
2009-06-13 12:21 . 2001-09-19 08:00 367374 ----a-w- c:\windows\system32\perfh001.dat
2009-06-11 21:53 . 2009-04-30 22:00 893807 ----a-w- c:\documents and settings\mohammad\Application Data\PlusBrowse\uojkjdpr.exe
2009-06-11 21:53 . 2009-04-30 21:54 447343 ----a-w- c:\documents and settings\mohammad\Application Data\PlusBrowse\qzzfouxq.exe
2009-06-11 21:53 . 2009-02-26 14:15 516975 ----a-w- c:\documents and settings\mohammad\Application Data\PlusBrowse\deaf dent does bash.exe
2009-06-11 21:53 . 2009-02-26 14:14 930671 ----a-w- c:\documents and settings\mohammad\Application Data\PlusBrowse\ajofsrcl.exe
2009-06-04 15:23 . 2009-05-02 16:12 290816 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\PlusBrowse\Creativeexitbase.exe
2009-06-04 15:22 . 2009-05-02 16:12 339968 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\PlusBrowse\deaf dent does bash.exe
2009-06-03 22:14 . 2009-02-28 12:21 528384 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\PlusBrowse\Rule Draw.exe
2009-05-19 21:23 . 2009-02-19 06:57 111976 ----a-w- c:\documents and settings\mohammad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-19 16:05 . 2009-02-28 12:03 111976 ----a-w- c:\documents and settings\ع ــزيز درملي\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-13 11:36 . 2009-05-13 11:36 741376 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\PlusBrowse\tpcbecxo.exe
2009-05-13 11:25 . 2009-05-13 11:25 741376 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\PlusBrowse\qhkauudo.exe
2009-05-13 05:02 . 2004-08-03 17:55 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-11 21:22 . 2009-05-11 21:22 -------- d-----w- c:\program files\XemiComputers
2009-05-09 18:47 . 2009-05-09 18:47 704512 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\PlusBrowse\enzshwbf.exe
2009-05-07 15:32 . 2004-08-03 17:55 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-04 20:25 . 2009-05-04 20:25 -------- d-----w- c:\program files\No-IP
2009-05-03 15:37 . 2009-05-03 15:37 0 ----a-w- c:\windows\system32\cd.dat
2009-05-02 16:11 . 2009-05-02 16:11 915456 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\PlusBrowse\qbxlbgsg.exe
2009-05-02 10:03 . 2009-05-02 10:03 761856 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\PlusBrowse\mgapihsq.exe
2009-05-01 09:52 . 2009-05-01 09:52 711168 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\PlusBrowse\euihuoth.exe
2009-04-29 11:59 . 2009-04-29 11:59 730624 ----a-w- c:\documents and settings\ع ــزيز درملي\Application Data\PlusBrowse\oltehikv.exe
2009-04-29 02:13 . 2009-04-29 02:13 -------- d-----w- c:\documents and settings\ع ــزيز درملي\Application Data\DMCache
2009-04-26 12:53 . 2009-04-26 12:53 0 ----a-w- c:\windows\nsreg.dat
2009-04-25 11:47 . 2009-04-25 11:47 -------- d-----w- c:\program files\Angle Interactive
2009-04-21 17:45 . 2009-04-21 17:45 35363 ----a-w- c:\windows\system32\windrvNT.sys
2009-04-21 17:45 . 2009-04-21 17:45 -------- d-----w- c:\program files\Folder Lock
2009-04-19 19:47 . 2004-08-03 17:46 1847040 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:52 . 2004-08-03 17:55 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-08 18:57 . 2009-04-08 18:57 196608 ----a-w- c:\windows\system32\maag.dll
2009-04-08 18:57 . 2009-02-19 06:55 1212416 ----a-w- c:\windows\system32\ckll.dll
2009-04-08 18:57 . 2009-02-19 06:55 90112 ----a-w- c:\windows\system32\agsaami.dll
2009-04-08 18:57 . 2009-02-19 06:55 610304 ----a-w- c:\windows\system32\agsaamg.dll
2009-04-08 18:57 . 2009-02-19 06:55 372736 ----a-w- c:\windows\system32\agsaamc.dll
2009-04-08 18:57 . 2009-02-19 06:55 2535424 ----a-w- c:\windows\system32\agsaamj.dll
2009-04-08 18:57 . 2009-02-19 06:55 1986560 ----a-w- c:\windows\system32\akll.dll
2009-04-08 18:57 . 2009-02-19 06:55 1245184 ----a-w- c:\windows\system32\bkll.dll
2009-04-03 18:18 . 2009-04-03 18:18 33256 ----a-w- c:\windows\system32\drivers\HssDrv.sys
2009-03-10 14:44 . 2009-03-10 14:44 655360 ------w- c:\program files\Common Files\NSV
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
2009-06-01 21:41 2094616 ----a-w- c:\program files\Hotspot_Shield\tbHot0.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-09 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2007-07-26 270336]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-19 136600]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-20 1601304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"LiveZilla"="c:\program files\SPAUN\LiveZilla\LiveZilla.exe" [2009-01-13 2603096]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-16 198160]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2005-03-07 53248]
"VTTrayp"="VTtrayp.exe" - c:\windows\system32\VTTrayp.exe [2005-10-31 163840]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-11-11 90112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-20 10:52 10520 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\AppServ\\Apache2.2\\bin\\httpd.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [19/02/2009 10:10 ص 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [19/02/2009 10:10 ص 107272]
R1 is-1IFFNdrv;is-1IFFNdrv;c:\windows\system32\drivers\37872614.sys [13/06/2009 06:58 م 148496]
R1 is-KRMFOdrv;is-KRMFOdrv;c:\windows\system32\drivers\70448432.sys [12/06/2009 09:59 م 148496]
R2 Apache2.2;Apache2.2;c:\appserv\Apache2.2\bin\httpd.exe [27/07/2006 12:49 م 20539]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [19/02/2009 10:10 ص 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [19/02/2009 10:10 ص 298264]
R2 HssSrv;Hotspot Shield Helper Service;c:\program files\Hotspot Shield\HssWPR\hsssrv.exe [22/04/2009 04:12 ص 328752]
S2 gupdate1c9eda4aa8407ee;خدمة تحديث Google (gupdate1c9eda4aa8407ee);c:\program files\Google\Update\GoogleUpdate.exe [15/06/2009 01:33 م 133104]
S3 HssTrayService;Hotspot Shield Tray Service;c:\program files\Hotspot Shield\bin\HssTrayService.exe [23/04/2009 12:34 ص 34352]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-16 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-06-15 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{3900B3B4-DC3B-48D3-A7BC-F24CB87DABC6}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 01:31]
2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{DF50DA65-208D-424A-BD4A-538F5DE2956E}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 01:31]
2009-06-16 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-15 10:32]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Base frag grid bows - c:\documents and settings\All Users\Application Data\Cast ping base frag\Debug Bib.exe
.
------- Supplementary Scan -------
.
uStart Page = about:Tabs
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-17 00:17
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\sccfg.sys 32768 bytes
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mysql]
"ImagePath"="c:\appserv\MySQL\bin\mysqld-nt --defaults-file=c:\appserv\MySQL\my.ini mysql"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1844237615-602162358-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*t*t* \OpenWithList]
@Class="Shell"
"a"="msnmsgr.exe"
"MRUList"="a"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2f5fe3f9-9810-4d56-9324-5da83ea91fb8}]
@Denied: (Full) (Everyone)
"Model"=dword:00000093
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):12,ad,52,59,fa,b8,8c,3d,93,f0,b6,eb,bd,95,d8,d4,4e,b2,c4,e5,e8,
95,f8,96,92,a9,3e,98,64,22,2f,8c,75,95,1a,ba,18,8e,26,eb,00,00,00,00,00,00,\
.
Completion time: 2009-06-16 0:19
ComboFix-quarantined-files.txt 2009-06-16 21:19
Pre-Run: 8,837,955,584 bytes free
Post-Run: 19,172,622,336 bytes free
214 --- E O F --- 2009-06-12 00:10