ComboFix 08-10-25.01 - xp 10/26/2008 19:28:52.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.160 [GMT 3:00]
Running from: C:\Documents and Settings\xp\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-09-26 to 2008-10-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-26 15:10 --------- d-----w C:\Program Files\Windows Installer Clean Up
2008-10-26 15:09 --------- d-----w C:\Program Files\MSECACHE
2008-10-26 15:05 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-16 07:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-13 15:41 --------- d-----w C:\Program Files\Common Files\Adobe
2008-10-08 00:46 --------- d-----w C:\Documents and Settings\xp\Application Data\Datalayer
2008-10-07 19:57 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-07 19:46 --------- d-----w C:\Program Files\Kelk 2000
2008-10-07 19:31 --------- d-----w C:\Documents and Settings\xp\Application Data\Free Download Manager
2008-10-07 19:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
2008-10-07 19:22 --------- d-----w C:\Documents and Settings\xp\Application Data\DMCache
2008-10-07 01:57 --------- d-----w C:\Documents and Settings\xp\Application Data\cleaner
2008-10-07 00:49 --------- d-----w C:\Documents and Settings\xp\Application Data\IDM
2008-10-04 15:39 --------- d-----w C:\Documents and Settings\xp\Application Data\Nokia Multimedia Player
2008-09-29 03:14 --------- d-----w C:\Documents and Settings\xp\Application Data\Nokia
2008-09-29 03:12 --------- d-----w C:\Program Files\DIFX
2008-09-29 03:12 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-09-29 03:12 --------- d-----w C:\Program Files\Common Files\Nokia
2008-09-29 03:12 --------- d-----w C:\Documents and Settings\xp\Application Data\PC Suite
2008-09-29 03:11 --------- d-----w C:\Program Files\Nokia
2008-09-29 03:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-09-26 16:15 --------- d-----w C:\Program Files\Your Uninstaller 2008
2008-09-19 16:00 --------- d-----w C:\Program Files\Windows Live
2008-09-19 15:55 --------- d-----w C:\Program Files\Microsoft
2008-09-15 15:24 1,846,272 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-12 22:02 4,313,598 ----a-w C:\WINDOWS\java\Packages\JHVLBXFP.ZIP
2008-09-11 19:52 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-09-11 19:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-09-10 14:53 --------- d-----w C:\Program Files\Alwil Software
2008-09-10 10:42 --------- d-----w C:\Program Files\Windows Defender
2008-09-10 10:30 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-09-08 21:03 51,712 ----a-w C:\WINDOWS\system32\sirenacm.dll
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-06 02:18 --------- d-----w C:\Documents and Settings\xp\Application Data\URSoft
2008-09-05 15:57 --------- d-----w C:\Program Files\JetAudio
2008-09-05 15:57 --------- d-----w C:\Documents and Settings\xp\Application Data\COWON
2008-09-05 11:32 --------- d-----w C:\Program Files\Astraware
2008-09-04 20:36 --------- d-----w C:\Documents and Settings\xp\Application Data\CyberScrub
2008-09-04 20:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ad Muncher
2008-09-04 03:19 --------- d-----w C:\Documents and Settings\xp\Application Data\Helexis
2008-09-04 00:06 --------- d-----w C:\Program Files\MSXML 6.0
2008-08-26 07:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:20 2,146,816 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:20 2,025,472 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-09 21:12 203,776 ----a-w C:\WINDOWS\system32\clrviddc.dll
2008-08-09 17:07 6,100 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-08-09 17:07 43,073 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-08-09 16:47 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-08-09 16:47 172,032 ------w C:\WINDOWS\Setup1.exe
2008-08-09 16:45 155,995 ----a-w C:\WINDOWS\java\Packages\HB3R3DBB.ZIP
2008-08-09 16:40 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-08-09 16:40 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
08/21/2008 03:15 PM 94736 --a------ C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [04/11/2006 05:52 PM 1409024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [08/09/2008 07:40 PM 185896]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [07/19/2008 05:38 PM 78008]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [08/24/2007 07:00 AM 33648]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [04/26/2006 08:29 AM 237568]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="C:\WINDOWS\Installer\TSClientMsiTrans\tscuinst.vbs" [10/30/2007 01:06 PM 13801]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [08/03/2004 11:59 PM 44544]
"nltide_3"="advpack.dll" [08/26/2008 10:57 AM 124928 C:\WINDOWS\system32\advpack.dll]
C:\Documents and Settings\xp\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [07/19/2008 05:35 PM 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [07/19/2008 05:37 PM 20560]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-10-26 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [11/03/2006 07:20 PM]
.
.
------- Supplementary Scan -------
.
R1 -: HKCU-Internet Settings,ProxyServer = http=TZPopupKiller:8100
R1 -: HKCU-Internet Settings,ProxyOverride = local
O8 -: Block frame with Ad Muncher -
O8 -: Block image with Ad Muncher -
O8 -: Block link with Ad Muncher -
O8 -: Don't filter page with Ad Muncher -
O8 -: Free Download Manager تحميل الفيديو بواسطة -
Files\Free Download Manager\dlfvideo.htm
O8 -: Report page to the Ad Muncher developers -
O8 -: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 -: ت&صدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 -: تحميل المحددة بفري داونلود مانيجر -
Files\Free Download Manager\dlselected.htm
O8 -: تنزيل الكل بفري داونلود مانيجر -
Files\Free Download Manager\dlall.htm
O8 -: تنزيل بفري داونلود مانيجر -
Files\Free Download Manager\dllink.htm
O16 -: Microsoft XML Parser for Java -
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-26 19:30:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 10/26/2008 19:31:18
ComboFix-quarantined-files.txt 2008-10-26 16:31:12
ComboFix2.txt 2008-10-26 16:26:16
Pre-Run: 38,667,530,240 bytes free
Post-Run: 38,655,885,312 bytes free
139 --- E O F --- 2008-10-24 18:23:42