ComboFix 09-03-23.01 - بـــــيـــلـــيه 03/25/2009 1:59:41.1 - NTFSx86
Microsoft® Windows Vista™ Business 6.0.6001.1.1256.1.1033.18.1014.411 [GMT 3:00]
Running from: d:\ابو فارع\ComboFix.exe
* Created a new restore point
.
The following files were disabled during the run:
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\A671~1\AppData\Local\Temp\b.bat
c:\users\A671~1\AppData\Local\Temp\E_4
c:\users\A671~1\AppData\Local\Temp\E_4\com.run
c:\users\A671~1\AppData\Local\Temp\E_4\dp1.fne
c:\users\A671~1\AppData\Local\Temp\E_4\eAPI.fne
c:\users\A671~1\AppData\Local\Temp\E_4\internet.fne
c:\users\A671~1\AppData\Local\Temp\E_4\krnln.fnr
c:\users\A671~1\AppData\Local\Temp\E_4\RegEx.fnr
c:\users\A671~1\AppData\Local\Temp\E_4\shell.fne
c:\users\A671~1\AppData\Local\Temp\E_4\spec.fne
.
((((((((((((((((((((((((( Files Created from 2009-02-24 to 2009-03-24 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-24 21:10 --------- d-----w c:\program files\DrWeb
2009-03-23 04:45 --------- d-----w c:\program files\Flash Memory Toolkit
2009-03-23 04:03 --------- d-----w c:\program files\Target Web ADS
2009-03-23 04:03 --------- d-----w c:\program files\ProDM
2009-03-23 04:00 --------- d-----w c:\program files\PCDR5
2009-03-23 02:57 --------- d-----w c:\program files\Ashampoo
2009-02-10 23:57 --------- d-----w c:\programdata\Microsoft Help
2008-09-26 03:05 174 --sh--w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7233CF20-0BA7-4fc2-879E-04CEF6439F90}]
03/23/2009 07:03 AM 86052 --a------ c:\program files\ProDM\ProDM.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8152A0B9-DEB6-476e-BC67-175B19080A8A}]
03/23/2009 07:03 AM 253956 --a------ c:\program files\Target Web ADS\TargetWebADS.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [01/19/2008 10:33 AM 1233920]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"Ashampoo AntiSpyWare 2 Guard"="c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWare2Guard.exe" [09/08/2008 11:09 AM 2349912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [12/21/2006 09:00 PM 56368]
"PMHandler"="c:\progra~1\Lenovo\PMDRIV~1\PMHandler.exe" [06/06/2007 03:11 AM 34352]
"snp2std"="c:\windows\vsnp2std.exe" [09/15/2006 11:21 PM 675840]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [10/23/2006 05:00 AM 815104]
"TPWAUDAP"="c:\program files\Lenovo\HOTKEY\TpWAudAp.exe" [09/06/2006 10:38 AM 54824]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [11/06/2006 03:02 AM 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [11/06/2006 03:05 AM 106496]
"Persistence"="c:\windows\system32\igfxpers.exe" [11/06/2006 03:02 AM 81920]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [12/14/2006 09:23 AM 536576]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [11/07/2006 01:51 PM 91688]
"OmniPass"="c:\program files\Softex\OmniPass\scureapp.exe" [12/21/2006 02:32 AM 2519040]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [12/16/2008 03:30 AM 136600]
"LPManager"="c:\progra~1\Lenovo\LENOVO~2\LPMGR.exe" [01/31/2007 08:01 PM 120368]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [11/16/2006 02:21 AM 217176]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [03/10/2007 12:23 AM 419376]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [03/10/2007 12:23 AM 120368]
"LenovoOobeOffers"="c:\swtools\LenovoWelcome\LenovoOobeOffers.exe" [12/29/2006 08:01 PM 28672]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [07/15/2008 05:10 AM 185896]
"AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [12/21/2006 12:51 PM 493104]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [08/24/2007 07:00 AM 33648]
"DB30E6"="c:\windows\system32\9DBC1E\DB30E6.EXE" [03/23/2009 01:27 AM 1516198]
"'Ashampoo AntiSpyWare 2 Guard'"="c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWare2Guard.exe" [09/08/2008 11:09 AM 2349912]
"RtHDVCpl"="RtHDVCpl.exe" [11/20/2006 08:13 AM 4018176 c:\windows\RtHDVCpl.exe]
c:\users\ •••••ï•••é•••ïى\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
??????.lnk - c:\windows\System32\9DBC1E\DB30E6.EXE [2009-03-23 1516198]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli ACGina
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{022267C3-0EDC-42DF-9D5B-208C8CC3D03F}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{186703FB-07BF-4B1C-B24D-5115C49D3C19}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{A5CC0F4C-A442-419B-91CD-BB5FFC608C9B}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{A04D086E-2C05-4853-A80F-D96434F9C1A3}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{BE9511EC-768B-45CB-83BC-7D1B259E21AB}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{802380BD-F35C-4001-BA39-9D2CFD84CDA4}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\System32\drivers\smiif32.sys [2006-10-20 13744]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\System32\drivers\tvti2c.sys [2006-09-13 35264]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [2006-11-02 167936]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\SystemVolumeInformation.exe
\shell\explore\Command - G:\SystemVolumeInformation.exe
\shell\open\Command - G:\SystemVolumeInformation.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a8ff97b0-fac9-11dd-95a4-000fb0d4b219}]
\shell\AutoRun\command - G:\SystemVolumeInformation.exe
\shell\explore\Command - G:\SystemVolumeInformation.exe
\shell\open\Command - G:\SystemVolumeInformation.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b4a0f051-1188-11de-8280-806e6f6e6963}]
\shell\AutoRun\command - G:\ioockw.bat
\shell\open\Command - G:\ioockw.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c195d1f2-5af9-11dd-a81f-000fb0d4b219}]
\shell\explore\command - G:\explorer.exe
\shell\open\Command - G:\explorer.exe
.
Contents of the 'Scheduled Tasks' folder
2008-11-14 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [01/08/2008 11:31 PM]
2009-03-24 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [02/13/2007 01:54 AM]
2009-03-24 c:\windows\Tasks\User_Feed_Synchronization-{7FB51E8E-F57E-4D8A-916A-1207E2509139}.job
- c:\windows\system32\msfeedssync.exe [01/19/2008 10:33 AM]
2009-03-24 c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
- c:\program files\Target Web ADS\TargetWebADSb.exe [03/23/2009 07:03 AM]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {EA3967A4-875B-47B2-97DD-D84A8790BD66} = 10.0.0.138
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-03-25 02:06:58
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(752)
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
- - - - - - - > 'lsass.exe'(780)
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
- - - - - - - > 'Explorer.exe'(4552)
c:\windows\system32\BROWSEUI.dll
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
c:\program files\Softex\OmniPass\SCUREDLL.dll
c:\users\A671~1\AppData\Local\Temp\catchme.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Softex\OmniPass\OmniServ.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\IPSSVC.EXE
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWareService.exe
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Lenovo\HOTKEY\FnF5svc.exe
c:\program files\Lenovo\PM Driver\PMSveH.exe
c:\program files\Lenovo\System Update\SUService.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\program files\Lenovo\HOTKEY\TPHKSVC.exe
c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe
c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\Common Files\Lenovo\Logger\logmon.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\program files\Softex\OmniPass\opvapp.exe
c:\windows\System32\conime.exe
c:\combofix\hidec.exe
c:\program files\Lenovo\PM Driver\PMHandler.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Lenovo\LenovoCare\LPMGR.EXE
c:\combofix\Catchme.tmp
.
**************************************************************************
.
Completion time: 03/25/2009 2:16:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-24 23:15:29
Pre-Run: 17,051,529,216 bytes free
Post-Run: 18,015,154,176 bytes free
193 --- E O F --- 2008-12-23 13:32:58