ComboFix 08-12-05.06 - welcome 12/06/2008 17:25:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.641 [GMT 3:00]
Running from: c:\documents and settings\welcome\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\welcome\Application Data\tazebama
c:\documents and settings\welcome\Application Data\tazebama\tazebama.log
c:\documents and settings\welcome\Application Data\tazebama\zPharaoh.dat
c:\windows\system32\hpowiax3.dll
c:\windows\system32\igfxres.dll
C:\zPharaoh.exe
d:\recycler\documents_backup.rar
d:\recycler\RECYCLER .exe
D:\zPharaoh.exe
.
((((((((((((((((((((((((( Files Created from 2008-11-06 to 2008-12-06 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-05 14:00 --------- d-----w c:\program files\MSN Messenger
2008-11-29 12:03 27,076,935 ----a-w C:\avg75free_484a1103.exe
2008-11-21 16:16 --------- d-----w c:\program files\Messenger Plus! Live
2008-11-21 16:16 --------- d-----w c:\program files\Circle Developement
2008-11-18 20:57 --------- d-----w c:\documents and settings\All Users\Application Data\Bluetooth
2008-11-18 20:53 --------- d-----w c:\program files\IVT Corporation
2008-11-17 15:17 --------- d-----w c:\documents and settings\welcome\Application Data\Nokia
2008-11-13 23:11 --------- d-----w c:\documents and settings\welcome\Application Data\ACD Systems
2008-11-13 15:59 --------- d-----w c:\program files\Yahoo!
2008-11-13 15:58 --------- d-----w c:\program files\Common Files\ACD Systems
2008-11-13 15:58 --------- d-----w c:\program files\ACD Systems
2008-11-13 15:58 --------- d-----w c:\documents and settings\All Users\Application Data\ACD Systems
2008-11-13 15:57 10,368 ----a-w c:\windows\system32\drivers\pfc.sys
2008-11-13 15:57 --------- d-----w c:\program files\Nero
2008-11-13 15:56 --------- d-----w c:\program files\mpegable
2008-11-13 15:54 --------- d-----w c:\program files\HP
2008-11-13 15:20 --------- d-----w c:\documents and settings\All Users\Application Data\HP
2008-11-13 15:09 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-11-13 15:09 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-11-13 15:09 --------- d-----w c:\program files\Common Files\xing shared
2008-11-13 15:09 --------- d-----w c:\program files\Common Files\Real
2008-11-13 15:05 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-13 15:04 --------- d-----w c:\program files\MSBuild
2008-11-13 15:04 --------- d-----w c:\program files\Microsoft Works
2008-11-13 14:54 512,096 ----a-w c:\windows\system32\drivers\amon.sys
2008-11-13 14:54 298,104 ----a-w c:\windows\system32\imon.dll
2008-11-13 14:54 15,424 ----a-w c:\windows\system32\drivers\nod32drv.sys
2008-11-13 14:51 --------- d-----w c:\program files\Windows Live
2008-11-13 14:51 --------- d-----w c:\program files\Adverts
2008-11-13 14:48 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2008-11-13 14:47 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-13 14:46 --------- d-----w c:\program files\CyberLink
2008-11-13 14:42 172,032 ------w c:\windows\Setup1.exe
2008-11-13 14:42 --------- d-----w c:\program files\Golden Al-Wafi Translator
2008-11-13 14:35 --------- d-----w c:\program files\Common Files\Adobe
2008-11-13 14:33 155,995 ----a-w c:\windows\java\Packages\AQ0EB3BZ.ZIP
2008-11-13 14:33 --------- d-----w c:\program files\Java
2008-11-13 14:32 --------- d-----w c:\program files\Common Files\Java
2008-11-13 08:51 --------- d-----w c:\documents and settings\welcome\Application Data\Media Player Classic
2008-11-13 08:50 --------- d-----w c:\documents and settings\All Users\Application Data\WinZip
2008-11-13 08:48 410,976 ----a-w c:\windows\system32\deploytk.dll
2008-11-13 08:46 --------- d-----w c:\program files\Real
2008-11-13 08:45 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-13 08:41 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-11-12 20:20 --------- d-----w c:\program files\ESET
2008-11-12 19:21 --------- d-----w c:\documents and settings\welcome\Application Data\Printer Info Cache
2008-11-12 19:21 --------- d-----w c:\documents and settings\welcome\Application Data\Image Zone Express
2008-11-12 18:51 --------- d-----w c:\documents and settings\All Users\Application Data\WEBREG
2008-11-12 18:49 --------- d-----w c:\documents and settings\welcome\Application Data\HP
2008-11-12 18:46 --------- d-----w c:\program files\Common Files\Hewlett-Packard
2008-11-12 18:45 --------- d-----w c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-11-12 17:57 --------- d-----w c:\program files\Synaptics
2008-11-12 17:57 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-12 17:32 --------- d-----w c:\program files\NetWaiting
2008-11-12 17:32 --------- d-----w c:\program files\CONEXANT
2008-11-12 17:30 --------- d-----w c:\program files\Broadcom
2008-11-12 17:30 --------- d-----w c:\documents and settings\welcome\Application Data\InstallShield
2008-11-12 17:29 --------- d-----w c:\program files\Intel
2008-11-12 17:25 --------- d-----w c:\program files\Hewlett-Packard
2008-11-12 16:45 --------- d-----w c:\program files\microsoft frontpage
2008-11-11 16:35 --------- d-----w c:\documents and settings\welcome\Application Data\proxy frag heart
2008-11-11 16:34 --------- d-----w c:\program files\proxy frag heart
2008-11-11 16:34 --------- d-----w c:\documents and settings\All Users\Application Data\Iso Web Bags Else
2008-11-11 16:29 229,743 ----a-w c:\windows\ST6UNST.EXE
2008-11-11 16:29 203,631 ----a-w c:\windows\AKDeInstall.exe
2008-11-11 15:46 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-10-16 11:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 11:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 11:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 11:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 11:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 11:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 11:08 34,328 ----a-w c:\windows\system32\wups.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"delete error"="c:\docume~1\welcome\APPLIC~1\PROXYF~1\dale4.exe" [11/11/2008 07:35 PM 721263]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [08/03/2004 10:32 PM 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [08/03/2004 10:32 PM 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [08/03/2004 10:32 PM 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [09/18/2007 10:29 PM 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [09/18/2007 10:29 PM 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [09/18/2007 10:29 PM 137752]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [01/12/2007 02:36 PM 827392]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [11/13/2008 11:48 AM 136600]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [02/07/2007 04:24 PM 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [11/11/2008 07:50 PM 211359]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM 31016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [11/13/2008 06:09 PM 185896]
"Bags Else Hole Lite"="c:\documents and settings\All Users\Application Data\Iso Web Bags Else\Browse jump.exe" [11/11/2008 07:37 PM 1865216]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 891399]
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-05-17 818303]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-04-28 415072]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-11-13 15424]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};\??\c:\program files\CyberLink\PowerDVD\
000.fcl [2006-11-02 16:51:58 13560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3da8088e-b00d-11dd-9e15-001cbf7a76f6}]
\Shell\AutoRun\command - F:\zPharaoh.exe
\Shell\explore\command - F:\zPharaoh.exe
\Shell\open\command - F:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{46ea3d02-b15e-11dd-9e0f-001cbf7a76f6}]
\Shell\AutoRun\command - F:\x.bat
\Shell\explore\Command - F:\x.bat
\Shell\open\Command - F:\x.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{46ea3d03-b15e-11dd-9e0f-001cbf7a76f6}]
\Shell\AutoRun\command - G:\xih9.cmd
\Shell\explore\Command - G:\xih9.cmd
\Shell\open\Command - G:\xih9.cmd
.
s of the 'Scheduled Tasks' folder
2008-12-06 c:\windows\Tasks\A53C6B0691B41C02.job
- c:\docume~1\welcome\applic~1\proxyf~1\second win help.exe [11/12/2008 05:26 PM]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
HKLM-Run-Device Detector - DevDetect.exe
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://codecs.r8.org/
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
O16 -: Microsoft XML Parser for Java -
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-06 17:28:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\
000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(992)
c:\windows\system32\imon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\ACD Systems\EN\DevDetect.exe
c:\program files\ESET\nod32krn.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 12/06/2008 17:29:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-06 14:29:44
Pre-Run: 30,473,572,352 bytes free
Post-Run: 30,514,327,552 bytes free
209