تفضل أخوي أن شاء الله خير:d:
ComboFix 09-04-25.03 - USER 04/25/2009 14:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.255.77 [GMT 4:00]
Running from: c:\documents and settings\USER\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\LocalService\Application Data\twain_32
c:\documents and settings\LocalService\Application Data\twain_32\user.ds
c:\documents and settings\NetworkService\Application Data\twain_32
c:\documents and settings\NetworkService\Application Data\twain_32\user.ds
c:\program files\FunWebProducts
c:\program files\FunWebProducts\Installr\1.bin\F3EZSETP.DLL
c:\program files\Microsoft Common
c:\program files\Microsoft Common\svchost.exe
c:\system\S-1-5-21-1482476501-1644491937-682003330-1013
c:\system\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
C:\test.txt
c:\windows\ktd32.atm
c:\windows\system32\Bifrost
c:\windows\system32\Bifrost\logg.dat
c:\windows\system32\dlds8.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\k86.bin
c:\windows\system32\kakle.dll
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\twain_32
c:\windows\system32\twain_32\local.ds
c:\windows\system32\twain_32\user.ds
c:\windows\system32\twain32
c:\windows\system32\twain32\local.ds
c:\windows\system32\twain32\user.ds
c:\windows\system32\vx.tll
c:\windows\system32\WanPacket.dll
c:\windows\system32\winitn.dll
c:\windows\system32\wpcap.dll
c:\windows\wiaserviv.log
c:\windows\win.exe
c:\windows\winhelp.ini
d:\recycler\office_crack.rar
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Legacy_POWERMANAGER
-------\Service_NPF
-------\Service_PowerManager
((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-4-25 )))))))))))))))))))))))))))))))
.
2009-04-24 18:54 . 2009-04-24 18:54 646 ----a-w c:\windows\system32\%LocalXml%
2009-04-24 17:55 . 2009-04-24 17:55 -------- d-----w c:\program files\Trend Micro
2009-04-23 18:46 . 2009-04-24 10:49 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-04-23 18:46 . 2009-04-24 10:49 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-04-23 18:28 . 2009-04-25 10:01 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-23 18:28 . 2009-04-23 18:28 -------- d-----w c:\program files\Kaspersky Lab
2009-04-23 18:28 . 2009-04-25 10:17 409632 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-23 18:28 . 2009-04-25 10:17 3528 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-23 18:28 . 2009-04-24 23:14 2290208 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-23 18:28 . 2009-04-24 23:14 20020 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-23 12:45 . 2008-10-16 10:06 27496 ----a-w c:\windows\system32\mucltui.dll.mui
2009-04-23 12:45 . 2008-10-16 10:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-04-23 12:45 . 2008-10-16 10:06 208744 ----a-w c:\windows\system32\muweb.dll
2009-04-23 11:52 . 2009-04-23 11:52 -------- dc----w c:\documents and settings\All Users\Application Data\{81D4BDA8-1F33-4633-B176-8A7E942ABDE1}
2009-04-23 04:47 . 2009-04-23 04:47 -------- d-----w c:\documents and settings\USER\Local Settings\Application Data\Stardock
2009-04-23 04:38 . 2009-04-23 12:47 -------- d-----w c:\program files\Paltalk Messenger
2009-04-22 19:10 . 2007-12-29 13:33 -------- d-----w C:\netcat
2009-04-21 13:44 . 2009-04-21 13:44 90153 ----a-w c:\documents and settings\USER\update.exe
2009-04-21 10:15 . 2005-01-27 17:13 607744 ----a-w c:\windows\system32\urlmon.backup
2009-04-21 10:15 . 2004-08-03 22:56 37888 ----a-w c:\windows\system32\url.backup
2009-04-21 10:15 . 2005-01-27 17:13 1483264 ----a-w c:\windows\system32\shdocvw.backup
2009-04-21 10:15 . 2004-08-03 22:56 549376 ----a-w c:\windows\system32\shdoclc.backup
2009-04-21 10:15 . 2005-01-27 17:13 1016832 ----a-w c:\windows\system32\browseui.backup
2009-04-21 10:15 . 2004-08-03 22:56 358400 ----a-w c:\windows\system32\inetcpl.backup
2009-04-21 10:14 . 2001-08-23 12:00 90112 ----a-w c:\windows\system32\mycomput.backup
2009-04-21 10:12 . 2008-07-18 18:10 53448 ----a-w c:\windows\system32\wuauclt.backup
2009-04-21 10:12 . 2004-08-03 22:56 183808 ----a-w c:\windows\system32\accwiz.backup
2009-04-21 10:12 . 2004-08-03 22:56 337920 ----a-w c:\windows\system32\zipfldr.backup
2009-04-21 10:12 . 2004-08-03 22:56 2897920 ----a-w c:\windows\system32\xpsp2res.backup
2009-04-21 10:12 . 2004-08-03 22:56 589312 ----a-w c:\windows\system32\wiashext.backup
2009-04-21 10:12 . 2004-08-03 22:56 276480 ----a-w c:\windows\system32\webcheck.backup
2009-04-21 10:12 . 2004-08-03 22:56 191488 ----a-w c:\windows\system32\syncui.backup
2009-04-21 10:12 . 2004-08-03 22:56 438272 ----a-w c:\windows\system32\shimgvw.backup
2009-04-21 10:12 . 2004-12-21 20:49 8450048 ----a-w c:\windows\system32\shell32.backup
2009-04-21 10:10 . 2005-01-27 17:13 3006976 ----a-w c:\windows\system32\mshtml.backup
2009-04-21 10:01 . 2004-08-03 22:56 218624 ----a-w c:\windows\system32\uxtheme.backup
2009-04-21 10:01 . 2004-08-03 22:56 514560 ----a-w c:\windows\system32\logonui.backup
2009-04-21 10:00 . 2009-04-21 10:15 -------- d-----w c:\windows\Icon_Patcher
2009-04-21 09:54 . 2009-04-21 09:54 -------- d-----w C:\Temp
2009-04-20 19:01 . 2008-01-29 21:41 25216 ----a-w c:\windows\system32\drivers\tap0901.sys
2009-04-19 14:45 . 2009-04-19 14:45 -------- d-----w c:\program files\WinPcap
2009-04-19 14:43 . 2009-04-19 14:51 -------- d-----w c:\program files\Cain
2009-04-18 19:58 . 2009-04-18 19:58 75951 ----a-w c:\windows\Test.jpg
2009-04-18 19:58 . 2009-04-18 19:58 2359350 ----a-w c:\windows\Test.bmp
2009-04-18 19:17 . 2009-04-20 10:30 20866 ----a-w c:\windows\OF.sys
2009-04-18 17:53 . 2009-04-23 12:35 -------- d-----w c:\windows\system32\Ads
2009-04-17 16:53 . 2009-04-17 16:53 -------- d-sh--r C:\BIN
2009-04-17 16:53 . 2009-04-17 16:53 33795 ----a-w c:\documents and settings\USER\cDFDF.EXE
2009-04-17 15:13 . 2009-04-17 15:13 -------- d-sh--r C:\Driver
2009-04-17 13:40 . 2009-04-20 17:33 -------- d-----w c:\program files\update
2009-04-16 13:55 . 2009-04-16 13:55 -------- d-----w c:\program files\Microsoft.NET
2009-04-16 03:46 . 2009-04-16 05:51 -------- d--h--w c:\windows\Bifrost
2009-04-16 03:46 . 2009-04-16 03:46 24693 ---h--w c:\documents and settings\USER\Application Data\addons.exe
2009-04-15 12:48 . 2009-04-15 12:50 -------- d--h--w c:\windows\system32\GroupPolicy
2009-04-11 20:25 . 2009-04-11 20:25 0 ----a-w c:\windows\system32\dmram.sys
2009-04-11 18:11 . 2009-04-23 07:31 2181888 ----a-w c:\windows\system32\kernel1.exe
2009-04-11 18:11 . 2009-04-11 19:07 2193280 ----a-w c:\windows\system32\KERNEL.TMP
2009-04-11 18:06 . 2008-02-17 03:39 211 --sha-w C:\BOOT.BKK
2009-04-11 15:01 . 2009-04-11 15:01 -------- d-----w c:\program files\Windows Live SkyDrive
2009-04-11 14:52 . 2009-04-11 14:52 -------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2009-04-11 14:45 . 2004-08-03 22:56 77312 ----a-w c:\windows\system32\msiexec.exe
2009-04-11 14:45 . 2004-08-03 22:56 77312 ----a-w c:\windows\system32\dllcache\msiexec.exe
2009-04-11 14:45 . 2004-08-03 22:56 44032 ----a-w c:\windows\system32\msisip.dll
2009-04-11 14:45 . 2004-08-03 22:56 44032 ----a-w c:\windows\system32\dllcache\msisip.dll
2009-04-11 14:45 . 2004-08-03 22:56 331264 ----a-w c:\windows\system32\msihnd.dll
2009-04-11 14:45 . 2004-08-03 22:56 331264 ----a-w c:\windows\system32\dllcache\msihnd.dll
2009-04-11 14:45 . 2004-08-03 22:56 2804224 ----a-w c:\windows\system32\msi.dll
2009-04-11 14:45 . 2004-08-03 22:56 2804224 ----a-w c:\windows\system32\dllcache\msi.dll
2009-04-11 14:45 . 2004-08-03 22:56 884736 ----a-w c:\windows\system32\msimsg.dll
2009-04-11 14:45 . 2004-08-03 22:56 884736 ----a-w c:\windows\system32\dllcache\msimsg.dll
2009-04-11 13:10 . 2009-04-21 08:28 45 ----a-w C:\TEST.XML
2009-04-11 13:06 . 2009-04-11 13:06 86016 ----a-w c:\windows\system32\wh18tokl.dll
2009-04-11 13:06 . 2009-04-11 13:06 1952 ----a-w c:\windows\system32\sys18h.dll
2009-04-11 11:51 . 2009-04-11 11:51 -------- d-----w c:\program files\TGTSoft
2009-04-09 11:59 . 2009-04-09 11:59 589 ----a-w c:\windows\pass.html
2009-04-09 11:58 . 2009-04-09 11:58 33 ----a-w c:\windows\mspass.bat
2009-04-09 05:39 . 2009-04-09 05:44 -------- d-----w c:\program files\ASProtect 1.35 Demo
2009-04-09 05:15 . 2009-04-09 05:24 -------- d-----w c:\documents and settings\USER\Application Data\Resource Tuner
2009-04-07 13:41 . 2008-10-25 16:23 480832 ----a-w c:\windows\system32\openport.exe
2009-04-07 11:13 . 2009-04-09 11:11 -------- d-----w c:\program files\Ivacy Monitor
2009-04-05 09:30 . 2009-04-05 09:30 -------- d-----w c:\program files\BreakPoint Software
2009-04-03 15:24 . 2009-04-07 13:55 44069 ----a-w c:\windows\3104.jpeg
2009-04-02 23:02 . 2009-04-19 19:51 54156 ---ha-w c:\windows\QTFont.qfn
2009-04-02 23:02 . 2009-04-02 23:02 1409 ----a-w c:\windows\QTFont.for
2009-04-02 17:24 . 2009-04-02 17:24 -------- d-----w c:\program files\Opera
2009-03-29 19:02 . 2009-04-24 14:30 -------- d-----w c:\program files\Common Files\Multilizer 2007
2009-03-29 19:00 . 2009-04-24 14:30 -------- d-----w c:\program files\Multilizer2007
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-25 10:18 . 2009-03-08 14:36 1632 ----a-w c:\windows\system32\d3d8caps.dat
2009-04-24 10:56 . 2008-01-29 13:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-04-21 10:14 . 2004-08-03 22:56 863744 ----a-w c:\windows\system32\shdoclc.dll
2009-04-21 10:09 . 2008-02-17 03:45 83456 ----a-w c:\windows\system32\charmap.exe
2009-04-21 10:01 . 2004-08-03 22:56 218624 ----a-w c:\windows\system32\uxtheme.dll
2009-04-21 10:01 . 2004-08-03 22:56 1949184 ----a-w c:\windows\system32\logonui.exe
2009-04-16 05:41 . 2008-12-14 13:58 -------- d-----w c:\program files\Common Files\Autodesk Shared
2009-04-16 05:38 . 2009-03-19 18:24 -------- d-----w c:\program files\CamStudio
2009-04-16 05:34 . 2008-11-02 16:32 -------- d-----w c:\program files\Acoustica Shared Effects
2009-04-16 05:34 . 2008-11-02 16:32 -------- d-----w c:\program files\Acoustica Mixcraft
2009-04-16 04:47 . 2008-12-16 18:21 -------- d-----w c:\program files\Classic Menu for Office
2009-04-11 14:33 . 2009-01-16 09:04 -------- d-----w c:\program files\MSN Messenger
2009-04-07 13:48 . 2009-03-20 09:03 -------- d-----w c:\program files\No-IP
2009-04-05 08:13 . 2009-03-12 11:57 -------- d-----w c:\program files\Opera 9.5 beta
2009-04-05 02:39 . 2008-02-17 05:07 226248 ----a-w c:\documents and settings\USER\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-03 13:03 . 2008-10-13 17:18 1744 ----a-w c:\windows\system32\d3d9caps.dat
2009-03-26 22:33 . 2009-03-26 22:24 44191 ----a-w C:\testlog.txt
2009-03-23 17:59 . 2009-03-23 12:41 987501 ----a-w c:\documents and settings\USER\dasda.exe
2009-03-21 18:40 . 2009-03-21 18:40 -------- d-----w c:\documents and settings\USER\Application Data\AdobeUM
2009-03-18 23:14 . 2009-03-18 23:14 -------- d-----w c:\program files\Microsoft Windows Security Update
2009-03-18 23:14 . 2009-03-18 23:14 987501 ----a-w c:\documents and settings\USER\dada.exe
2009-03-16 20:04 . 2009-03-16 20:04 -------- d-----w c:\documents and settings\All Users\Application Data\Installations
2009-03-16 19:55 . 2009-03-16 19:55 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2009-03-16 19:54 . 2009-03-16 19:54 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-03-12 15:06 . 2008-02-17 05:37 -------- d-----w c:\program files\Golden Al-Wafi Translator
2009-03-12 08:35 . 2008-11-12 22:53 -------- d-----w c:\program files\LeapFTP
2009-03-11 07:04 . 2009-01-16 08:39 -------- d-----w c:\program files\RegCleaner
2009-03-02 18:40 . 2008-12-06 17:55 -------- d-----w c:\program files\Circle Developement
2009-03-01 12:30 . 2009-03-01 12:01 -------- d-----w c:\program files\Kelk 2000
2009-02-28 15:30 . 2008-11-06 05:07 -------- d-----w c:\program files\TurboFTP
2009-02-28 13:00 . 2008-11-06 05:09 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-06 14:52 . 2009-02-06 14:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-05 20:24 . 2008-02-17 05:35 1245184 ----a-w c:\windows\system32\bkll.dll
2009-02-05 20:24 . 2008-11-02 19:26 215552 ----a-w c:\windows\system32\ALOWMVFile.dll
2009-02-05 20:24 . 2008-11-02 19:25 403968 ----a-w c:\windows\system32\ALOWMAFile2.dll
2009-02-05 20:23 . 2008-11-02 19:25 188416 ----a-w c:\windows\system32\ALOVideoFile.dll
2009-02-05 20:23 . 2008-02-17 05:35 2846720 ----a-w c:\windows\system32\agsaamj.dll
2009-02-05 20:23 . 2008-11-02 19:24 495104 ----a-w c:\windows\system32\ALOVideoCoreM.dll
2009-02-05 20:23 . 2008-02-17 05:35 90112 ----a-w c:\windows\system32\agsaami.dll
2009-02-05 20:22 . 2008-11-02 19:24 626688 ----a-w c:\windows\system32\agsaamh.dll
2009-02-05 20:22 . 2008-02-17 05:35 753664 ----a-w c:\windows\system32\agsaamg.dll
2009-02-05 20:22 . 2008-11-02 19:23 780288 ----a-w c:\windows\system32\ALOVideoCompress.dll
2009-02-05 20:21 . 2008-11-02 19:24 551424 ----a-w c:\windows\system32\agsaame.dll
2009-02-05 20:21 . 2008-11-02 19:23 249856 ----a-w c:\windows\system32\ALOQuickTimeFile.dll
2009-02-05 20:21 . 2008-11-02 19:23 90112 ----a-w c:\windows\system32\ALOAudioFormatSettings3.dll
2009-02-05 20:21 . 2008-11-02 19:23 382464 ----a-w c:\windows\system32\ALOAVIFile.dll
2009-02-05 20:21 . 2008-11-02 19:23 877568 ----a-w c:\windows\system32\ALOAudioFile2.dll
2009-02-05 20:21 . 2008-11-02 19:23 2846720 ----a-w c:\windows\system32\ALOAudioCompress3.dll
2009-02-05 20:21 . 2008-11-02 19:23 544256 ----a-w c:\windows\system32\agsaamd.dll
2009-02-05 20:21 . 2008-02-17 05:35 372736 ----a-w c:\windows\system32\agsaamc.dll
2009-02-05 20:20 . 2008-11-02 19:23 538624 ----a-w c:\windows\system32\agsaamb.dll
2009-02-05 20:20 . 2008-11-02 19:22 331776 ----a-w c:\windows\system32\agsaama.dll
2009-02-05 20:20 . 2008-11-02 19:22 778240 ----a-w c:\windows\system32\ALOAudioCompress2.dll
2009-02-05 20:19 . 2008-11-02 19:22 81920 ----a-w c:\windows\system32\viscomwave.dll
2009-02-05 20:19 . 2008-11-02 19:22 98304 ----a-w c:\windows\system32\viscomtran.dll
2009-02-05 20:18 . 2008-11-02 19:22 48640 ----a-w c:\windows\system32\viscomsamplerate.dll
2009-02-05 20:18 . 2008-11-02 19:22 118784 ----a-w c:\windows\system32\viscomrmenc.dll
2009-02-05 20:18 . 2008-11-02 19:22 147456 ----a-w c:\windows\system32\viscomqtenc.dll
2009-02-05 20:18 . 2008-11-02 19:22 602112 ----a-w c:\windows\system32\viscomqtde.dll
2009-02-05 20:18 . 2008-11-02 19:22 1470464 ----a-w c:\windows\system32\viscomm4aenc.dll
2009-02-05 20:18 . 2008-11-02 19:22 86016 ----a-w c:\windows\system32\viscomframe.dll
2009-02-05 20:18 . 2008-11-02 19:22 1462272 ----a-w c:\windows\system32\viscomflvenc.dll
2009-02-05 20:18 . 2008-11-02 19:22 118784 ----a-w c:\windows\system32\viscomflvdec.dll
2009-02-05 20:18 . 2008-11-02 19:22 1470464 ----a-w c:\windows\system32\viscomdata3.dll
2009-02-05 20:17 . 2008-11-02 19:22 1454080 ----a-w c:\windows\system32\viscomdata2.dll
2009-02-05 20:16 . 2008-11-02 19:22 1462272 ----a-w c:\windows\system32\viscomdata1.dll
2009-02-05 20:15 . 2008-11-02 19:23 344064 ----a-w c:\windows\system32\dkll.dll
2009-02-05 20:15 . 2008-02-17 05:35 196608 ----a-w c:\windows\system32\maag.dll
2009-02-05 20:15 . 2008-11-02 19:22 18628608 ----a-w c:\windows\system32\viscomavi.dll
2009-02-05 20:15 . 2008-02-17 05:35 1212416 ----a-w c:\windows\system32\ckll.dll
2009-02-05 20:15 . 2008-11-02 19:22 110592 ----a-w c:\windows\system32\viscomaudioencoder.dll
2009-02-05 20:15 . 2008-11-02 19:22 94208 ----a-w c:\windows\system32\viscomaudiodata.dll
2009-02-05 20:15 . 2008-11-02 19:22 1454080 ----a-w c:\windows\system32\viscomamrenc.dll
2009-02-05 20:15 . 2008-11-02 19:22 1462272 ----a-w c:\windows\system32\viscom3gpenc.dll
2009-02-05 20:15 . 2008-11-02 19:22 6963712 ----a-w c:\windows\system32\videotrans.dll
2009-02-05 20:14 . 2008-11-02 19:22 452608 ----a-w c:\windows\system32\videoformat.dll
2009-02-05 20:14 . 2008-11-02 19:22 18599936 ----a-w c:\windows\system32\videoencode.dll
2009-02-05 20:14 . 2008-11-02 19:22 19456 ----a-w c:\windows\system32\videocore.dll
2009-02-05 20:14 . 2008-11-02 19:22 90112 ----a-w c:\windows\system32\ssvideo.dll
2009-02-05 20:14 . 2008-11-02 19:22 1128128 ----a-w c:\windows\system32\NMSDVDXU.dll
2009-02-05 20:14 . 2008-11-02 19:22 18595840 ----a-w c:\windows\system32\coredata.dll
2009-02-05 20:14 . 2008-02-17 05:35 1986560 ----a-w c:\windows\system32\akll.dll
2009-02-04 05:41 . 2008-10-11 12:46 1854 ----a-w c:\windows\mozver.dat
2009-01-30 22:31 . 2009-01-30 22:31 9729 ----a-w c:\windows\system32\shutdown.zip
2008-09-14 11:42 . 2008-10-14 11:42 59 ----a-w c:\documents and settings\USER\Local Settings\Application Data\SUMQU0C1-FE20-APII-YE7M-BEDSDWMY5R6A.dat
2008-09-14 11:41 . 2008-10-14 11:41 82 ----a-w c:\documents and settings\All Users\Application Data\SUMQU0C1-FE20-APII-YE7M-BEDSDWMY5R6A.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 1443072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-11 185872]
"GroupManager"="c:\program files\Microsoft Windows Security Update\groupmanager.exe" [2009-03-18 32256]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-04-24 206088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\USER\Start Menu\Programs\Startup\
No-IP DUC.lnk - c:\program files\No-IP\DUC20.exe [2009-4-7 1172992]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-2-17 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\program files\TGTSoft\StyleXP\Logon\CurrentLogon.EXE"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmram.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CaptureWiz.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\CaptureWiz.lnk
backup=c:\windows\pss\CaptureWiz.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Autodesk\\3dsMax8\\3dsmax.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\LeapFTP\\LeapFTP.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"d:\\My Pictures\\مجلد خاص\\azooz\\king\\msn-imatawen\\Msn Admin v3.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"d:\\My Pictures\\مجلد خاص\\azooz\\king\\ViRuSMaN\\Poison Ivy 2.3.0\\Sa3eka Open Ports.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"d:\\My Pictures\\مجلد خاص\\azooz\\king\\Asb May 2.2.exe"=
"d:\\My Pictures\\مجلد خاص\\azooz\\king\\BiFrOsT_BaD_BoY\\DZ-GENIUSES Copy 1.2d.exe"=
"d:\\My Pictures\\مجلد خاص\\azooz\\king\\Spy-Net [RAT] v1.7\\spynet.exe"=
"d:\\My Pictures\\مجلد خاص\\azooz\\king\\BiFrOsT_BaD_BoY\\Bifrosta.exe"=
"d:\\My Pictures\\مجلد خاص\\azooz\\king\\Slh Final\\NewClient.exe"=
R1 b10dc63a;b10dc63a;c:\windows\System32\drivers\b10dc63a.sys [2008-10-23 0]
R1 dmram;MDRAM Connector;c:\windows\system32\dmram.sys [2009-04-11 0]
R2 LoIbeokcfa;LoIbeokcfa;c:\windows\System32\svchost.exe [2004-08-03 14336]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\DRIVERS\A3AB.sys [2006-05-11 472096]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
R3 tap0901;TAP-Win32 Adapter V9;c:\windows\system32\DRIVERS\tap0901.sys [2008-01-29 25216]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-04-24 33808]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-03-13 33800]
S2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-03-13 472320]
S2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe [2004-08-03 14336]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
S2 Vcs;Vcs support;c:\windows\system32\Drivers\Vcs.sys [2002-12-10 6852]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
LoIbeokcfa
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0658e355-12db-11de-9ee7-0008024312ad}]
\Shell\AutoRun\command - f:\restore\k-1-3542-4232123213-7676767-8888886\Ogard.exe
\Shell\open\command - f:\restore\k-1-3542-4232123213-7676767-8888886\Ogard.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f9be976-14fb-11de-9eed-0008024312ad}]
\Shell\AutoRun\command - f:\restore\k-1-3542-4232123213-7676767-8888886\Ogard.exe
\Shell\open\command - f:\restore\k-1-3542-4232123213-7676767-8888886\Ogard.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{78ec65c0-2c5e-11de-9f26-0008024312ad}]
\Shell\AutoRun\command - f:\driver\Files\Drago.exe
\Shell\open\command - f:\driver\Files\Drago.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{89c059cd-a4d1-11dd-9e38-0008024312ad}]
\Shell\AutoRun\command - SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\OgarD.exe
\Shell\open\command - SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\OgarD.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9c68003e-1b8d-11de-9efe-0008024312ad}]
\Shell\AutoRun\command - f:\bin\RECYCLE\Bin.exe
\Shell\open\command - f:\bin\RECYCLE\Bin.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ac4a3506-936a-11dd-be03-0008024312ad}]
\Shell\AutoRun\command - F:\zPharaoh.exe
\Shell\explore\command - F:\zPharaoh.exe
\Shell\open\command - F:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{feb83075-9522-11dd-9e16-0008024312ad}]
\Shell\AutoRun\command - f:\system\S-1-5-21-1482476501-1644491937-682003330-1013\OgarD.exe
\Shell\open\command - f:\system\S-1-5-21-1482476501-1644491937-682003330-1013\OgarD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{67KLN5J0-4OPM-00WE-AAX5-74CC2A322142}]
c:\driver\Files\Drago.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{67KLN5J0-4OPM-00WE-AAX5-74CC2A323342}]
c:\bin\RECYCLE\Bin.exe
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
Notify-hpstp - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ae/
mStart Page = hxxp://home.sweetim.com
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
Trusted Zone: hotmail.com\www
Trusted Zone: lycos.co.uk\members
Trusted Zone: nizwa7.com\www
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-25 14:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(688)
c:\windows\system32\cscui.dll
- - - - - - - > 'explorer.exe'(5928)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\msi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
.
Completion time: 2009-04-25 14:29
ComboFix-quarantined-files.txt 2009-04-25 10:28
Pre-Run: 2,331,295,744 bytes free
Post-Run: 2,373,251,072 bytes free
366