ComboFix 09-04-04.01 - Administrator 04/06/2009 3:13:00.1 - [color=red][b]FAT32[/b][/color]x86
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
c:\windows\system32\vbscript.dll is missing
.
((((((((((((((((((((((((( Files Created from 2009-03-06 to 2009-04-06 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-05 23:58 --------- d-----w c:\program files\K.BrontOk
2009-03-30 00:39 --------- d-----w c:\program files\AvaFind
2009-03-23 16:53 --------- d-----w c:\program files\Java
2009-03-20 22:15 --------- d-----w c:\program files\R-Studio
2009-03-18 11:44 --------- d-----w c:\documents and settings\Administrator\Application Data\IDM
2009-03-18 11:44 --------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2009-03-18 11:43 --------- d-----w c:\program files\Internet Download Manager
2009-03-10 20:42 --------- d-----w c:\documents and settings\Administrator\Application Data\AvaFind Data
2009-03-09 18:07 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-03-09 17:16 155,995 ----a-w c:\windows\java\Packages\XVRRFDBR.ZIP
2009-03-09 16:17 --------- d-----w c:\program files\Windows Live
2009-03-09 16:17 --------- d-----w c:\program files\Messenger Plus! Live
2009-03-09 16:17 --------- d-----w c:\program files\memookaybend
2009-03-09 16:17 --------- d-----w c:\program files\Circle Deelopement
2009-03-09 16:14 --------- d-----w c:\documents and settings\All Users\Application Data\Audio 4 part browse
2009-03-09 16:12 --------- d-----w c:\documents and settings\Administrator\Application Data\memookaybend
2009-03-09 16:10 --------- d-----w c:\program files\MessengerPlus! 3
2009-03-09 11:47 499,712 ----a-w c:\windows\system32\msvcp71.dll
2009-03-09 11:47 --------- d-----w c:\program files\Real
2009-03-09 11:47 --------- d-----w c:\program files\Common Files\xing shared
2009-03-09 11:47 --------- d-----w c:\program files\Common Files\Real
2009-03-09 11:08 --------- d-----w c:\program files\MSN Messenger
2009-03-08 20:19 4,096 ----a-w c:\windows\gdrv.sys
2009-03-08 18:50 --------- d-----w c:\program files\Common Files\Windows Live
2009-03-08 15:58 --------- d-----w c:\program files\Common Files\Adobe
2009-03-08 15:58 --------- d-----w c:\documents and settings\Administrator\Application Data\InterTrust
2009-03-08 12:54 --------- d-----w c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-02-09 14:15 1,846,144 ----a-w c:\windows\system32\win32k.sys
2009-02-09 14:15 1,846,144 ----a-w c:\windows\system32\dllcache\win32k.sys
.
------- Sigcheck -------
04/15/2008 01:37 PM 501248 02b900d9e95e4d560b4ee224b0bac0b6 c:\windows\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:00 PM 15360]
"heck jump"="c:\docume~1\ADMINI~1\APPLIC~1\MEMOOK~1\HopeRuleFlaw.exe" [03/09/2009 07:17 PM 704512]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [03/09/2009 07:10 PM 263752]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [01/19/2007 12:55 PM 5846384]
"AvaFind"="c:\program files\AvaFind\AvaFind.exe" [10/02/2003 01:36 AM 739328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\AntiVir PersonalEdition Classic\avgnt.exe" [04/02/2007 10:35 AM 405544]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [03/09/2009 02:47 PM 271888]
"Part browse safe hold"="c:\documents and settings\All Users\Application Data\Audio 4 part browse\mode mix.exe" [03/24/2009 11:12 PM 897024]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:00 PM 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= c:\\Program Files\\MSN Messenger\\MsnMsgr.Exe
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\Program Files\\AntiVir PersonalEdition Classic\\avguard.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Audio 4 part browse\\mode mix.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
S3 abp470n5;abp470n5; [x]
--- Other Services/Drivers In Memory ---
*Deregistered* - abp470n5
*Deregistered* - AFD
*Deregistered* - AntiVirScheduler
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - avgio
*Deregistered* - avipbb
*Deregistered* - Beep
*Deregistered* - BITS
*Deregistered* - BlueletAudio
*Deregistered* - Browser
*Deregistered* - BTHidEnum
*Deregistered* - BTHidMgr
*Deregistered* - Cdfs
*Deregistered* - clr_optimization_v2.0.50727_32
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - ImapiService
*Deregistered* - IpFilterDriver
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - mdmxsdk
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Nokia USB Port
*Deregistered* - Npfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - ssmdrv
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - VComm
*Deregistered* - VcommMgr
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder
2009-04-06 c:\windows\Tasks\AB91BA6691A22FFA.job
- c:\docume~1\admini~1\applic~1\memook~1\liesbirdoption.exe [03/09/2009 07:19 PM]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Settings,ProxyOverride = local
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\1p08y8d2.default\
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-06 03:15:05
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 04/06/2009 3:16:06
ComboFix-quarantined-files.txt 2009-04-06 00:16:06
Pre-Run: 15,642,918,912 bytes free
Post-Run: 16,028,958,720 bytes free
229 --- E O F --- 2009-03-11 06:39:50