ComboFix 09-07-02.02 - uers 12/03/2009 12:11.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.1913.1422 [GMT 3:00]
Running from: c:\documents and settings\uers\سطح المكتب\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-11-03 to 2009-12-03 )))))))))))))))))))))))))))))))
.
2009-12-03 09:05 . 2009-12-03 09:05 -------- d-----w- c:\documents and settings\uers\Application Data\CyberScrub
2009-12-03 07:49 . 2009-12-03 07:49 -------- d-----w- c:\program files\Trend Micro
2009-12-02 15:19 . 2009-02-09 11:48 2017280 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-12-02 15:19 . 2009-02-09 11:48 2059264 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-12-02 15:19 . 2009-02-09 11:48 2182016 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-12-02 15:19 . 2009-02-09 11:48 2137600 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-12-02 14:13 . 2009-12-02 14:13 -------- d-----w- c:\documents and settings\uers\Local Settings\Application Data\Opera
2009-12-02 14:13 . 2009-12-02 14:24 -------- d-----w- c:\program files\Opera
2009-12-02 13:22 . 2009-12-02 13:22 -------- d-sh--w- c:\documents and settings\uers\IECompatCache
2009-12-02 13:21 . 2009-12-02 13:21 -------- d-sh--w- c:\documents and settings\uers\PrivacIE
2009-12-02 13:18 . 2009-12-02 13:18 -------- d-sh--w- c:\documents and settings\uers\IETldCache
2009-12-02 13:14 . 2009-12-02 13:14 -------- d-----w- c:\windows\ie8updates
2009-12-02 13:13 . 2009-12-02 16:30 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-12-02 13:12 . 2009-12-02 13:13 -------- dc-h--w- c:\windows\ie8
2009-12-02 13:12 . 2009-12-02 13:13 -------- d-----w- c:\windows\system32\ar-SA
2009-12-02 12:58 . 2008-06-14 17:59 271616 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-12-02 12:58 . 2008-06-14 17:59 271616 ------w- c:\windows\system32\drivers\bthport.sys
2009-12-02 12:58 . 2009-06-02 10:12 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-12-02 12:55 . 2009-04-30 21:13 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-12-02 12:55 . 2009-04-30 21:13 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-02 12:55 . 2009-04-30 21:13 1985024 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-12-02 12:54 . 2009-04-30 21:13 11064832 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-12-02 12:40 . 2009-12-03 00:01 -------- d--h--w- c:\windows\$hf_mig$
2009-12-02 10:48 . 2008-10-24 11:10 453632 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-12-02 04:51 . 2009-12-02 04:51 0 ----a-w- c:\windows\nsreg.dat
2009-12-02 04:51 . 2009-12-02 04:51 -------- d-----w- c:\documents and settings\uers\Local Settings\Application Data\Mozilla
2009-12-02 04:26 . 2009-12-02 04:26 10240 ----a-w- c:\documents and settings\uers\Application Data\GRETECH\GomPlayer\GrLauncherTempSetup.exe
2009-12-02 04:26 . 2007-03-22 10:46 126976 ----a-w- c:\documents and settings\uers\Application Data\GRETECH\GomPlayer\GrLauncher.exe
2009-12-01 19:12 . 2009-12-01 19:12 26421 ----a-w- c:\documents and settings\uers\Application Data\IDM\DwnlData\uers\javadl.sun_11\javadl.sun.com
2009-12-01 19:11 . 2009-12-01 19:11 -------- d-----w- c:\windows\Sun
2009-12-01 19:00 . 2009-11-30 13:13 76040 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtdix.sys
2009-12-01 19:00 . 2009-11-30 13:12 97928 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgldx86.sys
2009-12-01 18:59 . 2009-11-30 13:13 10520 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgrsstx.dll
2009-12-01 18:59 . 2009-11-30 13:12 26824 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgmfx86.sys
2009-12-01 18:59 . 2009-11-30 13:12 287000 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgrsx.exe
2009-12-01 18:59 . 2009-12-01 18:59 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-12-01 18:59 . 2009-12-01 18:59 -------- d-----w- c:\documents and settings\LocalService\قائمة ابدأ
2009-12-01 18:59 . 2009-12-01 18:59 -------- d-----w- c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-12-01 09:03 . 2009-12-01 09:03 1439488 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-12-01 09:03 . 2009-12-01 09:03 1085208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-12-01 09:03 . 2009-12-01 09:03 755992 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avginet.dll
2009-12-01 09:03 . 2009-12-01 09:03 587032 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgiproxy.exe
2009-11-30 20:40 . 2009-12-02 04:22 -------- d-----w- c:\documents and settings\uers\Contacts
2009-11-30 18:33 . 2009-11-30 18:33 -------- d-sh--w- c:\documents and settings\uers\UserData
2009-11-30 17:02 . 2009-11-30 17:02 376832 ----a-w- c:\windows\system32\AegisI5Installer.exe
2009-11-30 16:46 . 2006-11-15 05:00 528096 ----a-w- c:\windows\system32\drivers\ar5211.sys
2009-11-30 16:46 . 2005-06-21 10:32 28544 ----a-w- c:\windows\system32\drivers\callistx.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-03 09:13 . 2009-11-30 13:05 -------- d-----w- c:\documents and settings\uers\Application Data\DMCache
2009-12-03 09:11 . 2001-09-19 12:00 40316 ----a-w- c:\windows\system32\perfc001.dat
2009-12-03 09:11 . 2001-09-19 12:00 251946 ----a-w- c:\windows\system32\perfh001.dat
2009-12-03 09:07 . 2009-11-30 13:12 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-12-03 09:04 . 2009-12-03 09:04 -------- d-----w- c:\documents and settings\uers\Application Data\cleaner
2009-12-01 18:59 . 2009-11-30 13:13 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-01 18:59 . 2009-11-30 13:12 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-01 18:59 . 2009-11-30 13:12 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-01 18:59 . 2009-11-30 13:13 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-30 17:03 . 2009-11-30 13:44 -------- d-----w- c:\program files\Intel
2009-11-30 16:46 . 2009-11-30 13:37 -------- d-----w- c:\program files\Atheros
2009-11-30 16:46 . 2009-11-30 13:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-30 15:40 . 2009-11-30 15:40 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-30 14:22 . 2009-11-30 12:50 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-30 14:16 . 2009-11-30 13:33 -------- d-----w- c:\program files\Toshiba
2009-11-30 14:16 . 2009-11-30 14:16 -------- d-----w- c:\program files\O2Micro Flash Memory Card Driver
2009-11-30 14:08 . 2009-11-30 13:42 -------- d-----w- c:\program files\CONEXANT
2009-11-30 14:07 . 2009-11-30 14:07 -------- d-----w- c:\program files\Synaptics
2009-11-30 14:06 . 2009-11-30 13:33 -------- d-----w- c:\program files\Common Files\InstallShield
2009-11-30 13:50 . 2009-11-30 13:12 -------- d-----w- c:\documents and settings\uers\Application Data\AVGTOOLBAR
2009-11-30 13:48 . 2009-11-30 13:48 -------- d-----w- c:\program files\Marvell
2009-11-30 13:47 . 2009-11-30 13:47 -------- d-----w- c:\documents and settings\uers\Application Data\TMP
2009-11-30 13:44 . 2009-11-30 13:44 -------- d-----w- c:\documents and settings\uers\Application Data\Intel
2009-11-30 13:44 . 2009-11-30 13:44 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Intel
2009-11-30 13:44 . 2009-11-30 13:44 -------- d-----w- c:\documents and settings\LocalService\Application Data\Intel
2009-11-30 13:44 . 2009-11-30 13:44 -------- d-----w- c:\documents and settings\Default User\Application Data\Intel
2009-11-30 13:44 . 2009-11-30 13:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel
2009-11-30 13:38 . 2009-11-30 13:38 -------- d-----w- c:\program files\Camera Assistant Software for Toshiba
2009-11-30 13:37 . 2009-11-30 13:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Atheros
2009-11-30 13:36 . 2009-11-30 13:36 -------- d-----w- c:\program files\REALTEK RTL8187B Wireless LAN Driver
2009-11-30 13:36 . 2009-11-30 13:36 -------- d-----w- c:\documents and settings\uers\Application Data\InstallShield
2009-11-30 13:35 . 2009-11-30 13:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-11-30 13:29 . 2009-11-30 13:29 -------- d-----w- c:\program files\Circle Developement
2009-11-30 13:29 . 2009-11-30 13:29 -------- d-----w- c:\program files\Messenger Plus! Live
2009-11-30 13:29 . 2009-11-30 13:29 -------- d-----w- c:\program files\Windows Live
2009-11-30 13:29 . 2009-11-30 13:28 -------- d-----w- c:\program files\MSN Messenger
2009-11-30 13:29 . 2009-11-30 13:29 99496 ----a-w- c:\documents and settings\uers\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-30 13:28 . 2009-11-30 13:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-30 13:19 . 2009-11-30 13:19 -------- d-----w- c:\program files\Microsoft Works
2009-11-30 13:18 . 2009-11-30 13:18 -------- d-----w- c:\program files\MSBuild
2009-11-30 13:12 . 2009-11-30 13:12 -------- d-----w- c:\program files\AVG
2009-11-30 13:10 . 2009-11-30 13:05 -------- d-----w- c:\program files\Internet Download Manager
2009-11-30 13:07 . 2009-11-30 13:07 2232 ----a-w- c:\windows\java\Packages\Data\VR37XJ1N.DAT
2009-11-30 13:07 . 2009-11-30 13:07 155995 ----a-w- c:\windows\java\Packages\RLNR1N5B.ZIP
2009-11-30 13:07 . 2009-11-30 13:07 2678 ----a-w- c:\windows\java\Packages\Data\U3LN5NBP.DAT
2009-11-30 13:07 . 2009-11-30 13:07 2678 ----a-w- c:\windows\java\Packages\Data\TJVVFX7H.DAT
2009-11-30 13:07 . 2009-11-30 13:07 2678 ----a-w- c:\windows\java\Packages\Data\Q04Q93JR.DAT
2009-11-30 13:07 . 2009-11-30 13:07 2678 ----a-w- c:\windows\java\Packages\Data\KUDNDZ5B.DAT
2009-11-30 13:07 . 2009-11-30 13:07 2678 ----a-w- c:\windows\java\Packages\Data\HNJJTRVH.DAT
2009-11-30 13:06 . 2009-11-30 13:06 -------- d-----w- c:\program files\Java
2009-11-30 13:06 . 2009-11-30 13:05 -------- d-----w- c:\documents and settings\uers\Application Data\IDM
2009-11-30 13:06 . 2009-11-30 13:06 -------- d-----w- c:\program files\Common Files\Java
2009-11-30 13:05 . 2009-11-30 13:05 198064 ----a-w- c:\documents and settings\uers\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
2009-11-30 13:03 . 2009-11-30 13:03 -------- d-----w- c:\documents and settings\All Users\Application Data\GRETECH
2009-11-30 13:03 . 2009-11-30 13:03 -------- d-----w- c:\documents and settings\uers\Application Data\GRETECH
2009-11-30 13:03 . 2009-11-30 13:03 -------- d-----w- c:\program files\GRETECH
2009-11-30 13:02 . 2009-11-30 13:02 -------- d-----w- c:\program files\Common Files\xing shared
2009-11-30 13:02 . 2009-11-30 13:02 -------- d-----w- c:\program files\Real
2009-11-30 13:02 . 2009-11-30 13:02 -------- d-----w- c:\program files\Common Files\Real
2009-11-30 13:02 . 2009-11-30 13:02 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-11-30 13:02 . 2009-11-30 13:02 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-11-30 13:00 . 2009-11-30 13:00 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-11-30 13:00 . 2009-11-30 12:59 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-30 12:50 . 2009-11-30 12:50 -------- d-----w- c:\program files\microsoft frontpage
2009-11-30 12:47 . 2009-11-30 12:47 22144 ----a-w- c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-12-01 2794928]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-03 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-11-30 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-01 1948440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Toshiba Hotkey Utility"="c:\program files\Toshiba\Windows Utilities\Hotkey.exe" [2008-05-09 1773568]
"ACU"="c:\program files\Atheros\ACU.exe" [2008-01-26 450648]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-10-25 413696]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-28 75136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-11-29 1024000]
"Toshiba Controls Utility"="c:\program files\TOSHIBA\Controls\VolumeIndicator.exe" [2008-02-01 77824]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-28 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-28 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-28 141848]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں*§ڑ\ںé*©ںê¤\*§ک ں颬نïé\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2008-4-14 2979144]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-11-30 122880]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-01 18:59 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\msncall.exe"=
"c:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPCS.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [30/11/2009 04:12 م 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [30/11/2009 04:13 م 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [01/12/2009 09:59 م 906520]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [01/12/2009 09:59 م 298776]
R3 CnxtHdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDAud.sys [30/11/2009 04:57 م 732160]
R3 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [30/11/2009 05:16 م 48600]
R3 QIOMem;Generic IO & Memory Access;c:\windows\system32\drivers\QIOMem.sys [29/05/2007 11:31 ص 6912]
R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [30/11/2009 04:37 م 57408]
S2 bxgofkrqs;Manager Network;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 12:56 ص 14336]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
bxgofkrqs
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-12-03 c:\windows\Tasks\User_Feed_Synchronization-{AE4597AE-1E9F-455D-A477-35BBA45C338A}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 01:31]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-INPROCOMMWireless - c:\program files\Atheros\Wireless\Utility\WlanUtil.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-12-03 12:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bxgofkrqs]
"ServiceDll"="c:\windows\system32\lsekt.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(280)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2009-12-03 12:14
ComboFix-quarantined-files.txt 2009-12-03 09:14
Pre-Run: 74,470,174,720 bytes free
Post-Run: 74,453,291,008 bytes free
221 --- E O F --- 2009-12-03 00:02