2009-09-18 11:42 . 2009-08-04 15:13 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-04-14 00:12 . 2008-09-10 01:14 1307648 c:\windows\system32\dllcache\msxml6.dll
- 2004-08-04 00:56 . 2008-09-04 16:42 1106944 c:\windows\system32\dllcache\msxml3.dll
+ 2004-08-04 00:56 . 2008-09-04 17:15 1106944 c:\windows\system32\dllcache\msxml3.dll
+ 2009-06-28 00:42 . 2009-06-10 16:19 2066432 c:\windows\system32\dllcache\mstscax.dll
+ 2009-07-18 16:05 . 2009-07-19 13:18 5937152 c:\windows\system32\dllcache\mshtml.dll
+ 2009-01-08 01:20 . 2009-01-08 01:20 1022976 c:\windows\system32\dllcache\browseui.dll
+ 2001-08-23 14:00 . 2008-04-14 00:11 1504256 c:\windows\system32\diskcopy.dll
- 2004-08-04 00:56 . 2009-06-26 16:18 1054208 c:\windows\system32\danim.dll
+ 2004-08-04 00:56 . 2008-04-14 00:11 1054208 c:\windows\system32\danim.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 1689088 c:\windows\system32\d3d9.dll
+ 2004-08-04 00:56 . 2008-04-14 00:11 1689088 c:\windows\system32\d3d9.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 1179648 c:\windows\system32\d3d8.dll
+ 2004-08-04 00:56 . 2008-04-14 00:11 1179648 c:\windows\system32\d3d8.dll
+ 2009-06-28 00:42 . 2008-04-14 00:11 1267200 c:\windows\system32\comsvcs.dll
+ 2004-08-04 00:56 . 2008-04-14 00:11 2091520 c:\windows\system32\cdosys.dll
+ 2004-08-04 00:56 . 2008-04-14 00:11 1025024 c:\windows\system32\browseui.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 1888992 c:\windows\system32\ati3duag.dll
+ 2009-06-28 00:44 . 2008-04-14 00:11 3166208 c:\windows\srchasst\msgr3en.dll
- 2009-06-28 00:44 . 2004-08-04 00:56 3166208 c:\windows\srchasst\msgr3en.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1695232 c:\windows\ServicePackFiles\ServicePackCache\i386\msmsgs.exe
+ 2008-04-13 17:39 . 2008-04-13 17:39 2897920 c:\windows\ServicePackFiles\i386\xpsp2res.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1135616 c:\windows\ServicePackFiles\i386\wuaueng.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 4256768 c:\windows\ServicePackFiles\i386\wmm2res.dll
+ 2008-04-13 16:48 . 2008-04-13 16:48 1647616 c:\windows\ServicePackFiles\i386\winbrand.dll
+ 2008-04-13 19:30 . 2008-04-13 19:30 1845632 c:\windows\ServicePackFiles\i386\win32k.sys
+ 2009-09-29 20:55 . 2004-07-17 11:35 1326080 c:\windows\ServicePackFiles\i386\webfldrs.msi
+ 2007-06-27 12:59 . 2007-06-27 12:59 1302528 c:\windows\ServicePackFiles\i386\system.xml.dll
+ 2007-06-27 12:59 . 2007-06-27 12:59 2002944 c:\windows\ServicePackFiles\i386\system.windows.forms.dll
+ 2007-12-17 12:00 . 2007-12-17 12:00 1200128 c:\windows\ServicePackFiles\i386\system.web.dll
+ 2007-06-27 12:58 . 2007-06-27 12:58 1695744 c:\windows\ServicePackFiles\i386\system.design.dll
+ 2007-06-27 12:58 . 2007-06-27 12:58 1179648 c:\windows\ServicePackFiles\i386\system.data.dll
+ 2007-12-17 11:59 . 2007-12-17 11:59 1179648 c:\windows\ServicePackFiles\i386\sy52106.dll
+ 2008-04-13 18:37 . 2008-04-13 18:37 2842112 c:\windows\ServicePackFiles\i386\sprb040d.dll
+ 2008-04-13 18:35 . 2008-04-13 18:35 2869248 c:\windows\ServicePackFiles\i386\sprb0401.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 2134528 c:\windows\ServicePackFiles\i386\smtpsnap.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 8461312 c:\windows\ServicePackFiles\i386\shell32.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1499136 c:\windows\ServicePackFiles\i386\shdocvw.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1614848 c:\windows\ServicePackFiles\i386\sfcfiles.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1435648 c:\windows\ServicePackFiles\i386\query.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1288192 c:\windows\ServicePackFiles\i386\quartz.dll
+ 2007-05-15 08:08 . 2007-05-15 08:08 1057280 c:\windows\ServicePackFiles\i386\pcl5ures.dll
+ 2007-05-15 08:08 . 2007-05-15 08:08 1058816 c:\windows\ServicePackFiles\i386\pcl5eres.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1287168 c:\windows\ServicePackFiles\i386\ole32.dll
+ 2009-09-29 20:55 . 2004-08-04 05:29 1897408 c:\windows\ServicePackFiles\i386\nv4_mini.sys
+ 2008-04-14 00:12 . 2008-04-14 00:12 4274816 c:\windows\ServicePackFiles\i386\nv4_disp.dll
+ 2008-04-13 19:27 . 2008-04-13 19:27 2188928 c:\windows\ServicePackFiles\i386\ntoskrnl.exe
+ 2008-04-13 18:31 . 2008-04-13 18:31 2023936 c:\windows\ServicePackFiles\i386\ntkrpamp.exe
+ 2008-04-13 18:31 . 2008-04-13 18:31 2065792 c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
+ 2008-04-13 19:24 . 2008-04-13 19:24 2145280 c:\windows\ServicePackFiles\i386\ntkrnlmp.exe
+ 2008-04-14 00:12 . 2008-04-14 00:12 1200640 c:\windows\ServicePackFiles\i386\ntbackup.exe
+ 2008-04-14 00:12 . 2008-04-14 00:12 1703936 c:\windows\ServicePackFiles\i386\netshell.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1737856 c:\windows\ServicePackFiles\i386\mtxparhd.dll
+ 2009-09-29 20:55 . 2004-08-04 05:41 1309184 c:\windows\ServicePackFiles\i386\mtlstrm.sys
+ 2008-04-14 00:12 . 2008-04-14 00:12 1104896 c:\windows\ServicePackFiles\i386\msxml3.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1428992 c:\windows\ServicePackFiles\i386\msvidctl.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1384479 c:\windows\ServicePackFiles\i386\msvbvm60.dll
+ 2008-04-13 16:23 . 2008-04-13 16:23 2479616 c:\windows\ServicePackFiles\i386\msoeres.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1314816 c:\windows\ServicePackFiles\i386\msoe.dll
+ 2009-09-29 20:55 . 2004-07-17 11:41 1327320 c:\windows\ServicePackFiles\i386\msnsusii.exe
+ 2009-09-29 20:55 . 2004-07-17 11:41 5080576 c:\windows\ServicePackFiles\i386\msnmsgs.msi
+ 2008-04-14 00:12 . 2008-04-14 00:12 1695232 c:\windows\ServicePackFiles\i386\msmsgs.exe
+ 2007-10-22 09:30 . 2007-10-22 09:30 1516568 c:\windows\ServicePackFiles\i386\msjet40.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 2843136 c:\windows\ServicePackFiles\i386\msi.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3066880 c:\windows\ServicePackFiles\i386\mshtml.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3166208 c:\windows\ServicePackFiles\i386\msgr3en.dll
+ 2007-12-17 11:59 . 2007-12-17 11:59 2281472 c:\windows\ServicePackFiles\i386\mscorwks.dll
+ 2007-12-17 11:58 . 2007-12-17 11:58 2273280 c:\windows\ServicePackFiles\i386\mscorsvr.dll
+ 2007-12-17 11:58 . 2007-12-17 11:58 1998848 c:\windows\ServicePackFiles\i386\mscorlib.dll
+ 2007-06-27 12:54 . 2007-06-27 12:54 1564672 c:\windows\ServicePackFiles\i386\mscorcfg.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 3558912 c:\windows\ServicePackFiles\i386\moviemk.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 1872896 c:\windows\ServicePackFiles\i386\mmcndmgr.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1414656 c:\windows\ServicePackFiles\i386\mmc.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 1028096 c:\windows\ServicePackFiles\i386\mfc42.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 2061824 c:\windows\ServicePackFiles\i386\lhmstscx.dll
+ 2009-09-29 20:55 . 2004-08-04 05:41 1041536 c:\windows\ServicePackFiles\i386\hsfdpsp2.sys
+ 2008-04-14 00:12 . 2008-04-14 00:12 1033728 c:\windows\ServicePackFiles\i386\explorer.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 1082368 c:\windows\ServicePackFiles\i386\esent.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 2113536 c:\windows\ServicePackFiles\i386\dxdiagn.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1298432 c:\windows\ServicePackFiles\i386\dxdiag.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 1227264 c:\windows\ServicePackFiles\i386\dx8vb.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 1293824 c:\windows\ServicePackFiles\i386\dsound3d.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 1504256 c:\windows\ServicePackFiles\i386\diskcopy.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 1054208 c:\windows\ServicePackFiles\i386\danim.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 1689088 c:\windows\ServicePackFiles\i386\d3d9.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 1179648 c:\windows\ServicePackFiles\i386\d3d8.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 1032192 c:\windows\ServicePackFiles\i386\conf.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 1267200 c:\windows\ServicePackFiles\i386\comsvcs.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 1358848 c:\windows\ServicePackFiles\i386\cimwin32.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 2091520 c:\windows\ServicePackFiles\i386\cdosys.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 1025024 c:\windows\ServicePackFiles\i386\browseui.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 1888992 c:\windows\ServicePackFiles\i386\ati3duag.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 1057760 c:\windows\ServicePackFiles\i386\ati3d2ag.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 1852928 c:\windows\ServicePackFiles\i386\acgenral.dll
+ 2008-06-11 22:05 . 2008-06-11 22:05 9994240 c:\windows\Installer\28d70c.msp
+ 2009-08-21 17:14 . 2009-08-21 17:14 8363008 c:\windows\Installer\126a281.msp
+ 2009-08-20 12:02 . 2009-08-20 12:02 5204992 c:\windows\Installer\126a265.msp
+ 2009-09-29 16:08 . 2009-09-29 16:08 6747648 c:\windows\Installer\126a24f.msp
+ 2009-09-21 23:53 . 2009-09-21 23:53 5518848 c:\windows\Installer\126a239.msp
+ 2007-06-06 17:53 . 2007-06-06 17:53 1195888 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.8173\FM20.DLL
+ 2009-10-02 17:19 . 2009-03-08 11:34 1206784 c:\windows\ie8updates\KB972260-IE8\urlmon.dll
+ 2009-10-02 17:19 . 2009-03-08 11:41 5937152 c:\windows\ie8updates\KB972260-IE8\mshtml.dll
+ 2009-10-02 17:19 . 2009-03-08 11:32 1985024 c:\windows\ie8updates\KB972260-IE8\iertutil.dll
+ 2009-10-02 07:38 . 2009-07-18 16:05 3069440 c:\windows\ie8\mshtml.dll
+ 2004-08-04 00:56 . 2008-04-14 00:12 1033728 c:\windows\explorer.exe
+ 2009-09-18 11:42 . 2009-08-05 03:44 2189184 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2009-09-18 11:42 . 2009-08-04 14:20 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-02-08 02:02 . 2009-08-04 14:20 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-09-18 11:42 . 2009-08-04 15:13 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2004-08-04 00:56 . 2008-04-14 00:11 1852928 c:\windows\AppPatch\acgenral.dll
+ 2009-09-20 11:38 . 2004-08-04 00:56 1287680 c:\windows\$NtUninstallKB971633_0$\quartz.dll
+ 2009-09-20 11:40 . 2004-08-03 23:18 2148352 c:\windows\$NtUninstallKB956572_0$\ntoskrnl.exe
+ 2009-09-20 11:40 . 2004-08-04 01:05 2015232 c:\windows\$NtUninstallKB956572_0$\ntkrnlpa.exe
+ 2009-09-30 10:07 . 2009-10-02 18:01 25198016 c:\windows\system32\MRT.exe
+ 2009-03-08 11:39 . 2009-07-20 01:48 11067392 c:\windows\system32\ieframe.dll
+ 2009-07-20 01:48 . 2009-07-20 01:48 11067392 c:\windows\system32\dllcache\ieframe.dll
+ 2009-06-28 00:48 . 2008-04-14 00:09 13463552 c:\windows\system32\dllcache\hwxjpn.dll
- 2009-06-28 00:48 . 2001-08-23 14:00 13463552 c:\windows\system32\dllcache\hwxjpn.dll
+ 2009-09-29 20:55 . 2004-07-17 11:41 11053008 c:\windows\ServicePackFiles\i386\msncli.exe
+ 2008-04-14 00:09 . 2008-04-14 00:09 13463552 c:\windows\ServicePackFiles\i386\lang\hwxjpn.dll
+ 2009-10-02 17:19 . 2009-03-08 11:39 11063808 c:\windows\ie8updates\KB972260-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-27 39408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-27 185896]
"ACU"="c:\program files\Atheros\ACU.exe" [2005-05-31 303104]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-09 149280]
"avp"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-07-03 303376]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2006-08-03 53248]
"S3Trayp"="S3trayp.exe" - c:\windows\system32\S3Trayp.exe [2006-07-11 176128]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-11-14 16270848]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\user\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mobily Connect Card\\Mobily Connect Card.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 06:29 م 33808]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [27/06/2009 05:56 م 13696]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 06:06 م 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16/05/2009 08:59 م 19472]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [14/08/2006 10:51 ص 654848]
.
Contents of the 'Scheduled Tasks' folder
2009-10-20 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 22:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = https=a:3
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-10-20 17:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1008)
c:\windows\system32\athgina.dll
c:\windows\system32\athcfg11.dll
c:\windows\system32\athcfg11Res.dll
.
Completion time: ~,10time:~,-3
ComboFix-quarantined-files.txt 2009-10-21 01:00
ComboFix2.txt 2009-09-30 10:19
ComboFix3.txt 2009-09-28 08:55
Pre-Run: 29,820,923,904 bytes free
Post-Run: 29,901,455,360 bytes free
- - End Of File - - 237C00DEA8C5FFC7F8687A1B7917802E