ComboFix 09-08-06.01 - asd 08/07/2009 20:22.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.511.289 [GMT 3:00]
Running from: c:\documents and settings\asd\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AIC32P
-------\Service_aic32p
((((((((((((((((((((((((( Files Created from 2009-07-07 to 2009-08-07 )))))))))))))))))))))))))))))))
.
2009-08-07 17:25 . 2009-08-07 17:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-08-07 17:09 . 2009-08-07 17:09 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-08-07 17:02 . 2009-08-07 17:02 -------- d-----w- c:\program files\مشغل الفلاش العربي
2009-08-07 16:52 . 2009-08-07 16:52 -------- d-----w- c:\windows\Sun
2009-08-07 16:42 . 2004-08-03 22:55 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-08-07 16:42 . 2009-08-07 16:42 -------- d-----w- c:\windows\system32\LogFiles
2009-08-07 16:41 . 2009-08-07 16:42 -------- d-----w- c:\windows\system32\drivers\umdf
2009-08-07 16:40 . 2006-05-09 17:00 22752 ----a-w- c:\windows\system32\spupdsvc.exe
2009-08-07 16:40 . 2009-08-07 16:41 -------- d-----w- C:\3a203f03932e651f9c62f4
2009-08-07 16:39 . 2009-08-07 16:39 -------- d-----w- c:\documents and settings\asd\Contacts
2009-08-07 16:38 . 2009-08-07 16:38 -------- d-----w- c:\program files\Windows Live
2009-08-07 16:38 . 2009-08-07 16:38 -------- d-----w- c:\program files\Messenger Plus! Live
2009-08-07 16:38 . 2009-08-07 16:38 -------- dc----w- c:\windows\system32\DRVSTORE
2009-08-07 16:38 . 2009-08-07 16:38 -------- d-----w- c:\program files\MSN Messenger
2009-08-07 16:34 . 2009-08-07 16:34 27264 ----a-w- c:\documents and settings\asd\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-07 16:19 . 2009-08-07 16:19 -------- d-s---w- c:\documents and settings\asd\UserData
2009-08-07 16:18 . 2009-08-07 16:18 -------- d-----w- c:\documents and settings\asd\Application Data\Yahoo!
2009-08-07 16:18 . 2009-08-07 16:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-08-07 16:09 . 2009-08-07 16:09 -------- d-----w- c:\documents and settings\asd\Local Settings\Application Data\ACD Systems
2009-08-07 16:09 . 2009-08-07 16:09 -------- d-----w- c:\documents and settings\asd\Application Data\ACD Systems
2009-08-07 16:09 . 2009-08-07 16:09 -------- d-----w- c:\program files\Yahoo!
2009-08-07 16:09 . 2009-08-07 16:09 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems
2009-08-07 16:09 . 2009-08-07 16:09 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-08-07 16:09 . 2009-08-07 16:09 -------- d-----w- c:\program files\ACD Systems
2009-08-07 16:07 . 2009-08-07 16:07 -------- d-----w- c:\documents and settings\asd\Local Settings\Application Data\Downloaded Installations
2009-08-07 16:05 . 2009-08-07 16:05 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-08-07 16:05 . 2004-08-03 20:08 26496 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2009-08-07 16:03 . 2009-08-07 16:04 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-07 16:01 . 2009-08-07 16:01 -------- d-----w- c:\program files\Sun
2009-08-07 15:59 . 2009-08-07 16:00 -------- d-----w- c:\program files\Java
2009-08-07 15:59 . 2009-08-07 15:59 -------- d-----w- c:\program files\Common Files\Java
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-07 16:46 . 2009-08-07 16:46 -------- d-----w- c:\program files\Common Files\xing shared
2009-08-07 16:46 . 2009-08-07 16:46 -------- d-----w- c:\program files\Common Files\Real
2009-08-07 16:46 . 2009-08-07 16:46 -------- d-----w- c:\program files\Google
2009-08-07 16:46 . 2009-08-07 16:46 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-08-07 16:46 . 2009-08-07 16:46 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-08-07 16:46 . 2009-08-07 16:46 -------- d-----w- c:\program files\Real
2009-08-07 11:25 . 2001-09-19 12:00 39982 ----a-w- c:\windows\system32\perfc001.dat
2009-08-07 11:25 . 2001-09-19 12:00 251478 ----a-w- c:\windows\system32\perfh001.dat
2009-08-07 11:20 . 2009-08-07 10:54 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-08-07 10:57 . 2009-08-07 10:57 -------- d-----w- c:\program files\microsoft frontpage
2009-08-07 10:56 . 2009-08-07 10:56 -------- d-----w- c:\program files\MSXML 4.0
2009-08-07 10:52 . 2009-08-07 10:52 22144 ----a-w- c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5743984]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2009-08-07 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 206224]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 96112]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-08-07 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [2007-04-23 12451]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-03 44544]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2004-08-03 99840]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\برامج كمبيوتر\\برامج مابعد الفورمات\\الجافا\\Java Version 6 Update 7.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
--- Other Services/Drivers In Memory ---
*NewlyCreated* - AIC32P
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Device Detector - DevDetect.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-08-07 20:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2988)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\ACD Systems\EN\DevDetect.exe
c:\windows\system32\notepad.exe
.
**************************************************************************
.
Completion time: 2009-08-07 20:28 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-07 17:28
Pre-Run: 22,619,185,152 bytes free
Post-Run: 22,499,545,088 bytes free
130 --- E O F --- 2009-08-07 11:38
ـــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــ
وهذا التقرير الثاني تعبناك معنا يا الغالي