ComboFix 09-06-30.03 - 1 06/30/2009 18:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.494.172 [GMT 3:00]
Running from: c:\documents and settings\1\سطح المكتب\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090630-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Kaspersky Anti-Virus 6.0 *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\str.sys
c:\windows\system32\url(3).dll
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-30 )))))))))))))))))))))))))))))))
.
2009-06-30 13:22 . 2009-06-30 15:57 0 ----a-w- C:\osy3.sys
2009-06-28 00:35 . 2009-06-28 02:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Ashampoo
2009-06-28 00:35 . 2009-06-28 12:05 -------- d-----w- c:\program files\Ashampoo
2009-06-28 00:35 . 2009-06-28 00:35 -------- d-----w- c:\documents and settings\All Users\Application Data\page
2009-06-26 22:06 . 2009-02-05 21:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-06-26 22:06 . 2009-02-05 21:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-06-26 22:06 . 2009-02-05 21:05 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-06-26 22:06 . 2009-02-05 21:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-06-26 22:06 . 2009-02-05 21:08 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-06-26 22:06 . 2009-02-05 21:08 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-06-26 22:06 . 2009-02-05 21:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-06-26 22:06 . 2009-02-05 21:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-06-26 22:06 . 2009-02-05 21:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-06-26 03:16 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-06-26 03:16 . 2009-06-26 03:16 -------- d-----w- c:\program files\Alwil Software
2009-06-26 02:30 . 2009-06-30 15:27 12024352 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-26 02:30 . 2009-06-28 11:55 69664 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-26 02:29 . 2009-06-26 02:29 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-26 02:29 . 2009-06-30 15:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-24 05:11 . 2009-06-24 05:11 -------- d-sh--w- c:\documents and settings\1\IECompatCache
2009-06-24 05:11 . 2009-06-24 05:11 -------- d-sh--w- c:\documents and settings\1\PrivacIE
2009-06-24 05:11 . 2009-06-24 05:11 -------- d-sh--w- c:\documents and settings\1\IETldCache
2009-06-24 05:04 . 2009-06-26 02:35 -------- dc-h--w- c:\windows\ie8
2009-06-24 01:12 . 2006-03-24 16:08 28778 ----a-w- c:\windows\system32\klogon.dll
2009-06-19 18:02 . 2009-06-19 18:02 -------- d-----w- c:\program files\Common Files\xing shared
2009-06-19 18:01 . 2009-06-19 18:01 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-06-19 18:01 . 2009-06-19 18:01 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-06-18 08:12 . 2009-06-18 08:12 -------- d-----w- c:\program files\General Removal
2009-06-10 15:57 . 2009-06-10 15:57 -------- d-----w- c:\documents and settings\1\Local Settings\Application Data\Real
2009-06-10 15:57 . 2009-06-10 15:57 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-06-10 15:57 . 2009-06-10 15:57 -------- d-----w- c:\program files\windowsafeeggs
2009-06-10 15:57 . 2009-06-10 15:57 -------- d-----w- c:\windows\Muslim Bag
2009-06-10 15:49 . 2009-06-10 15:57 -------- d-----w- c:\program files\Athan
2009-06-10 15:02 . 2009-06-10 15:02 -------- d-sh--w- c:\windows\system32\twain32
2009-06-02 20:49 . 2009-06-10 14:54 -------- d-----w- c:\program files\VDOWNLOADER
2009-06-02 20:40 . 2009-06-10 15:00 -------- d-----w- c:\program files\TubeSucker
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-30 15:43 . 2009-01-22 21:06 -------- d-----w- c:\program files\Google
2009-06-30 15:32 . 2001-09-19 12:00 41076 ----a-w- c:\windows\system32\perfc001.dat
2009-06-30 15:32 . 2001-09-19 12:00 254326 ----a-w- c:\windows\system32\perfh001.dat
2009-06-30 15:27 . 2009-06-26 02:30 164204 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-30 13:06 . 2009-02-19 22:21 -------- d-----w- c:\documents and settings\1\Application Data\windowsafeeggs
2009-06-28 12:44 . 2004-08-03 21:55 218624 ----a-w- c:\windows\system32\uxtheme.dll
2009-06-28 12:21 . 2009-04-28 10:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Grid Blue Memo Site
2009-06-28 11:55 . 2009-06-26 02:30 8432 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-19 18:40 . 2009-02-15 03:32 -------- d-----w- c:\program files\Save Flash
2009-06-19 18:02 . 2009-01-22 18:14 -------- d-----w- c:\program files\Common Files\Real
2009-06-14 14:51 . 2009-01-22 18:23 -------- d-----w- c:\program files\Circle Developement
2009-06-10 15:57 . 2009-04-24 10:20 -------- d-----w- c:\program files\SWiSHmax
2009-06-10 15:48 . 2009-05-11 09:23 -------- d-----w- c:\program files\Athan(2)
2009-06-10 15:12 . 2009-05-25 20:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-25 20:24 . 2009-05-25 20:24 -------- d-----w- c:\documents and settings\1\Application Data\Malwarebytes
2009-05-25 20:24 . 2009-05-25 20:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2009-02-15 171448]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"General Removal"="c:\\Program Files\\General Removal\\General_Removal.exe" [2009-04-12 623616]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-19 198160]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2005-03-07 53248]
"VTTrayp"="VTtrayp.exe" - c:\windows\system32\VTTrayp.exe [2005-10-31 163840]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-02-13 16857600]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\1\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Ela-Salaty.lnk - c:\program files\Ela-Salaty\Salaty.exe [2007-3-5 5205504]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-2-15 113664]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-1-22 122880]
«©م، ¢¬نïé Adobe Reader.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2279:TCP"= 2279:TCP:ifsyn
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [27/06/2009 01:06 ص 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [27/06/2009 01:06 ص 20560]
S2 gupdate1c9f108cc8b0e2;خدمة تحديث Google (gupdate1c9f108cc8b0e2);c:\program files\Google\Update\GoogleUpdate.exe [19/06/2009 09:01 م 133104]
S2 pcswhpd;Manager Network;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 12:56 ص 14336]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
pcswhpd
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-19 18:01]
2009-06-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-19 18:01]
2009-06-30 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-06-30 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-06-30 c:\windows\Tasks\User_Feed_Synchronization-{045D4E96-4F39-4640-95B6-51F83A3A15F8}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 23:01]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-UIWatcher - c:\program files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe
HKCU-Run-userloud - c:\docume~1\1\APPLIC~1\WINDOW~1\Bore16bone.exe
HKLM-Run-kav - c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
HKLM-Run-Athan - c:\program files\Athan\Athan.exe
HKLM-Run-memo site kind that - c:\documents and settings\All Users\Application Data\Grid Blue Memo Site\Cake win.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com.sa/
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-30 18:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pcswhpd]
"ServiceDll"="c:\windows\system32\eazzgl.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(752)
c:\windows\system32\klogon.dll
- - - - - - - > 'explorer.exe'(3864)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\rundll32.exe
c:\program files\General Removal\General_Removal.exe
c:\windows\system32\wscntfy.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2009-06-30 19:01 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-30 16:01
Pre-Run: 28,030,316,544 bytes free
Post-Run: 28,111,872,000 bytes free
187 --- E O F --- 2009-03-16 01:55