هذا تقرير البرنامج الاول
ComboFix 09-05-22.07 - aaa 05/22/2009 18:28.3 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.1014.812 [GMT 3:00]
Running from: c:\documents and settings\ass\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\system32\uxtheme(2).dll
.
((((((((((((((((((((((((( Files Created from 2009-04-22 to 2009-05-22 )))))))))))))))))))))))))))))))
.
2009-05-22 15:09 . 2009-05-22 15:09 -------- d-----w c:\program files\Trend Micro
2009-05-20 01:09 . 2009-05-20 01:09 -------- d-----w c:\documents and settings\ass\Local Settings\Application Data\GlobeTrotter Connect
2009-05-19 21:39 . 2009-05-19 21:39 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2009-05-18 20:41 . 2009-05-18 20:41 -------- d-----w c:\windows\system32\config\systemprofile\Application Data\ESET
2009-05-14 00:30 . 2008-05-15 07:08 104192 ----a-w c:\windows\system32\drivers\br3gmdm.sys
2009-05-12 23:31 . 2009-05-12 23:31 -------- d-----w c:\program files\Abadisoft
2009-05-12 23:22 . 2009-05-12 23:31 720896 ----a-w c:\windows\iun6002.exe
2009-05-12 22:51 . 2007-06-19 14:32 563016 ----a-w c:\windows\system32\WinPcap_4_0.exe
2009-05-12 19:09 . 2009-05-12 19:09 -------- d-----w c:\documents and settings\ass\Local Settings\Application Data\ESET
2009-05-12 00:50 . 2008-01-07 11:29 352 ---ha-w c:\windows\nod32fixtemdono.reg
2009-05-12 00:49 . 2009-05-12 00:49 -------- d-----w c:\documents and settings\ass\Application Data\ESET
2009-05-12 00:48 . 2009-05-12 00:48 -------- d-----w c:\program files\ESET
2009-05-12 00:48 . 2009-05-12 00:48 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-05-05 22:46 . 2009-05-05 22:46 -------- d-sh--w c:\documents and settings\ass\IECompatCache
2009-05-05 22:45 . 2009-05-05 22:45 -------- d-sh--w c:\documents and settings\ass\PrivacIE
2009-05-05 22:44 . 2009-05-05 22:44 -------- d-sh--w c:\documents and settings\ass\IETldCache
2009-05-05 22:18 . 2009-05-06 10:52 -------- d-----w c:\windows\ie8updates
2009-05-05 22:18 . 2009-02-28 04:55 105984 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-05-05 22:15 . 2009-02-20 18:09 78336 ----a-w c:\windows\system32\ieencode.dll
2009-05-05 22:15 . 2009-02-20 18:09 78336 ----a-w c:\windows\system32\dllcache\ieencode.dll
2009-05-05 14:49 . 2009-05-05 14:49 10134 ----a-r c:\documents and settings\ass\Application Data\Microsoft\Installer\{35725FBC-A136-4A46-9F29-091759D9BB93}\ARPPRODUCTICON.exe
2009-05-05 14:49 . 2009-05-05 14:49 10134 ----a-r c:\documents and settings\ass\Application Data\Microsoft\Installer\{EA516024-D84D-41F1-814F-83175A6188F2}\ARPPRODUCTICON.exe
2009-05-04 21:41 . 2006-03-02 11:41 77942 ----a-w c:\windows\system32\BisonRem.dll
2009-05-04 21:41 . 2005-01-14 10:47 180224 ----a-w c:\windows\system\StillDrv.dll
2009-05-04 21:40 . 2009-05-04 21:40 -------- d-----w c:\windows\BisonCam
2009-05-04 21:40 . 2006-06-30 07:40 775936 ----a-w c:\windows\system32\drivers\BisonCam.sys
2009-05-04 21:40 . 2006-03-29 21:05 90112 ----a-w c:\windows\system\BisonVfw.dll
2009-05-04 21:40 . 2006-03-29 21:05 126976 ----a-w c:\windows\system\BisonCam.dll
2009-04-28 22:57 . 2009-04-28 22:57 10134 ----a-r c:\documents and settings\ass\Application Data\Microsoft\Installer\{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}\ARPPRODUCTICON.exe
2009-04-28 22:57 . 2009-04-28 22:57 -------- d-----w c:\program files\HP
2009-04-28 22:40 . 2009-05-19 21:56 -------- d-----w c:\program files\WinWatermark 2
2009-04-24 13:36 . 2009-04-24 13:36 -------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2009-04-24 13:30 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-24 13:30 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-24 13:30 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-24 13:30 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-24 13:30 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-24 13:30 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-24 13:30 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-24 13:30 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-24 13:30 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-24 13:28 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-24 13:28 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-23 21:07 . 2009-04-23 21:07 81920 ----a-w c:\documents and settings\ass\Application Data\ezpinst.exe
2009-04-23 21:07 . 2009-04-23 21:07 47360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2009-04-23 21:07 . 2009-04-23 21:07 47360 ----a-w c:\documents and settings\ass\Application Data\pcouffin.sys
2009-04-23 21:07 . 2009-04-23 21:07 -------- d-----w c:\documents and settings\ass\Application Data\Vso
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-22 15:50 . 2009-02-22 15:59 -------- d-----w c:\documents and settings\ass\Application Data\DMCache
2009-05-21 17:32 . 2009-02-22 15:51 -------- d-----w c:\program files\Circle Developement
2009-05-14 00:30 . 2009-03-12 19:12 -------- d-----w c:\program files\BandRich
2009-05-09 20:33 . 2009-02-22 15:51 -------- d-----w c:\program files\Messenger Plus! Live
2009-05-04 21:40 . 2009-02-22 13:59 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-28 14:02 . 2009-04-05 17:41 -------- d-----w c:\documents and settings\All Users\Application Data\Cast ping base frag
2009-04-28 14:02 . 2009-04-05 17:41 -------- d-----w c:\documents and settings\ass\Application Data\free title
2009-04-24 22:12 . 2009-02-24 18:29 -------- d-----w c:\documents and settings\ass\Application Data\dvdcss
2009-04-24 15:52 . 2009-02-22 15:51 73792 ----a-w c:\documents and settings\ass\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-09 12:21 . 2007-12-21 05:21 55768 ----a-w c:\windows\system32\drivers\epfwtdi.sys
2009-04-09 12:21 . 2007-12-21 05:21 33096 ----a-w c:\windows\system32\drivers\epfwndis.sys
2009-04-09 12:21 . 2007-12-21 05:21 133000 ----a-w c:\windows\system32\drivers\epfw.sys
2009-04-09 12:18 . 2009-04-09 12:18 107256 ----a-w c:\windows\system32\drivers\ehdrv.sys
2009-04-09 12:10 . 2007-12-21 05:19 113960 ----a-w c:\windows\system32\drivers\eamon.sys
2009-04-08 19:02 . 2009-04-08 19:00 -------- d-----w c:\program files\Duplicate File Remover
2009-04-08 18:58 . 2009-04-08 18:48 -------- d-----w c:\program files\NoClone
2009-04-08 17:48 . 2009-02-22 14:23 -------- d-----w c:\program files\MSN Messenger
2009-04-08 17:48 . 2009-04-08 17:48 -------- d-----w c:\program files\Microsoft
2009-04-08 17:48 . 2009-02-22 15:51 -------- d-----w c:\program files\Windows Live
2009-04-08 17:47 . 2009-04-08 17:47 -------- d-----w c:\program files\Windows Live SkyDrive
2009-04-08 17:40 . 2009-04-08 17:40 -------- d-----w c:\program files\Common Files\Windows Live
2009-04-06 14:46 . 2009-04-06 14:46 -------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-04-06 14:46 . 2009-04-06 14:46 -------- d-----w c:\program files\QuickTime Alternative
2009-04-06 14:35 . 2009-04-06 14:35 -------- d-----w c:\program files\Common Files\xing shared
2009-04-06 14:35 . 2009-02-22 16:03 -------- d-----w c:\program files\Common Files\Real
2009-04-06 14:34 . 2009-02-22 16:03 -------- d-----w c:\program files\Real
2009-04-06 14:30 . 2009-04-06 14:30 -------- d-----w c:\program files\Real Alternative
2009-04-05 17:41 . 2009-04-05 17:41 -------- d-----w c:\program files\free title
2009-03-27 19:53 . 2009-03-27 19:53 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-03-27 19:53 . 2009-03-27 19:53 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-03-27 19:48 . 2009-03-27 19:25 -------- d-----w c:\documents and settings\All Users\Application Data\Installations
2009-03-27 19:48 . 2009-03-27 19:26 -------- d-----w c:\program files\Nokia
2009-03-27 19:46 . 2009-03-27 19:46 -------- d-----w c:\program files\Common Files\Nokia
2009-03-27 19:45 . 2009-03-27 19:45 3351812 ----a-w c:\documents and settings\All Users\Application Data\Installations\{EF4F620F-F295-41D7-92C0-6B635709C850}\Installer\CommonCustomActions\msxml6Exec.exe
2009-03-27 19:45 . 2009-03-27 19:45 36864 ----a-w c:\documents and settings\All Users\Application Data\Installations\{EF4F620F-F295-41D7-92C0-6B635709C850}\Installer\CommonCustomActions\Sleep.exe
2009-03-27 19:45 . 2009-03-27 19:45 3181612 ----a-w c:\documents and settings\All Users\Application Data\Installations\{EF4F620F-F295-41D7-92C0-6B635709C850}\Installer\CommonCustomActions\vcredistExec.exe
2009-03-27 19:45 . 2009-03-27 19:46 24568280 ----a-w c:\documents and settings\All Users\Application Data\Installations\{EF4F620F-F295-41D7-92C0-6B635709C850}\NokiaSoftwareUpdaterSetup_1.4.98AR.exe
2009-03-27 19:42 . 2009-03-27 19:42 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2009-03-27 19:42 . 2009-03-27 19:42 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-03-27 19:30 . 2009-03-27 19:30 -------- d-----w c:\documents and settings\All Users\Application Data\Nokia
2009-03-25 22:41 . 2009-03-25 21:57 -------- d-----w c:\program files\Mobily Connect Card
2009-03-11 20:43 . 2009-03-11 20:43 390664 ----a-w c:\documents and settings\ass\Application Data\Real\RealPlayer\setup\AU_setup6.exe
2009-03-06 14:22 . 2004-08-03 22:56 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-03 22:56 826368 ----a-w c:\windows\system32\wininet.dll
2009-03-01 20:31 . 2009-02-22 18:57 21361 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-02-27 06:07 . 2009-02-22 13:10 166455 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-02-27 05:01 . 2009-02-27 05:01 592 ----a-w c:\windows\chgkey.vbs
2009-02-22 15:59 . 2009-02-22 15:59 120240 ----a-w c:\documents and settings\ass\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
2009-02-22 15:48 . 2009-02-22 15:48 9856 ----a-w c:\windows\system32\drivers\pfc.sys
2009-02-22 13:08 . 2009-02-22 13:08 21640 ----a-w c:\windows\system32\emptyregdb.dat
.
------- Sigcheck -------
[-] 2004-08-03 22:56 14336 8F078AE4ED187AAABC0A305146DE6716 c:\windows\$NtServicePackUninstall$\svchost.exe
[-] 2008-04-14 00:12 14336 27C6D03BCDB8CFEB96B716F3D8BE3E18 c:\windows\ServicePackFiles\i386\svchost.exe
[-] 2008-04-14 00:12 14336 27C6D03BCDB8CFEB96B716F3D8BE3E18 c:\windows\system32\svchost.exe
[-] 2004-08-03 22:56 577024 C72661F8552ACE7C5C85E16A3CF505C4 c:\windows\$NtServicePackUninstall$\user32.dll
[-] 2008-04-14 00:12 578560 B26B135FF1B9F60C9388B4A7D16F600B c:\windows\ServicePackFiles\i386\user32.dll
[-] 2008-04-14 00:12 578560 B26B135FF1B9F60C9388B4A7D16F600B c:\windows\system32\user32.dll
[-] 2004-08-03 22:56 82944 2ED0B7F12A60F90092081C50FA0EC2B2 c:\windows\$NtServicePackUninstall$\ws2_32.dll
[-] 2008-04-14 00:12 82432 2CCC474EB85CEAA3E1FA1726580A3E5A c:\windows\ServicePackFiles\i386\ws2_32.dll
[-] 2008-04-14 00:12 82432 2CCC474EB85CEAA3E1FA1726580A3E5A c:\windows\system32\ws2_32.dll
[-] 2008-12-20 23:56 827904 044E0A4E9FE97C0FB9AFE9C89E2A82E6 c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll
[-] 2009-03-03 00:17 828416 C8667854873938CA13C986F16B0CD183 c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\wininet.dll
[-] 2004-08-03 22:56 656384 C0823FC5469663BA63E7DB88F9919D70 c:\windows\ie7\wininet.dll
[-] 2007-08-13 15:54 818688 A4A0FC92358F39538A6494C42EF99FE9 c:\windows\ie7updates\KB961260-IE7\wininet.dll
[-] 2008-12-20 23:15 826368 A82935D32D0672E8FF4E91AE398E901C c:\windows\ie7updates\KB963027-IE7\wininet.dll
[-] 2008-04-14 00:12 666112 7A4F775ABB2F1C97DEF3E73AFA2FAEDD c:\windows\ServicePackFiles\i386\wininet.dll
[-] 2009-03-03 00:18 826368 28775945CCD53DEE280EF58DEA1A94C4 c:\windows\system32\wininet.dll
[-] 2009-03-03 00:18 826368 28775945CCD53DEE280EF58DEA1A94C4 c:\windows\system32\dllcache\wininet.dll
[-] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[-] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[-] 2008-06-20 10:45 360320 2A5554FC5B1E04E131230E3CE035C3F9 c:\windows\$NtServicePackUninstall$\tcpip.sys
[-] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
[-] 2004-08-03 21:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB951748_0$\tcpip.sys
[-] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\system32\drivers\tcpip.sys
[-] 2004-08-03 22:56 502272 01C3346C241652F43AED8E2149881BFE c:\windows\$NtServicePackUninstall$\winlogon.exe
[-] 2008-04-14 00:12 507904 ED0EF0A136DEC83DF69F04118870003E c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-04-14 00:12 507904 ED0EF0A136DEC83DF69F04118870003E c:\windows\system32\winlogon.exe
[-] 2004-08-03 21:14 182912 558635D3AF1C7546D26067D5D9B6959E c:\windows\$NtServicePackUninstall$\ndis.sys
[-] 2008-04-13 19:20 182656 1DF7F42665C94B825322FAE71721130D c:\windows\ServicePackFiles\i386\ndis.sys
[-] 2008-04-13 19:20 182656 1DF7F42665C94B825322FAE71721130D c:\windows\system32\drivers\ndis.sys
[-] 2004-08-03 21:00 29056 4448006B6BC60E6C027932CFC38D6855 c:\windows\$NtServicePackUninstall$\ip6fw.sys
[-] 2008-04-13 18:53 36608 3BB22519A194418D5FEC05D800A19AD0 c:\windows\ServicePackFiles\i386\ip6fw.sys
[-] 2008-04-13 18:53 36608 3BB22519A194418D5FEC05D800A19AD0 c:\windows\system32\drivers\ip6fw.sys
[-] 2009-02-06 10:30 2066176 607352B9CB3D708C67F6039097801B5A c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[-] 2008-08-14 09:18 2062976 63EC865DFF6CCFC7BEF94B5C50297CAD c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
[-] 2008-08-14 09:33 2066048 4AC58F03EB94A72809949D757FC39D80 c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
[-] 2008-08-14 12:39 2066048 A25E9B86EFFB2AF33BF51E676B68BFB0 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
[-] 2008-08-14 09:22 2015744 DC097A896A03B8277457D228FD12D4E6 c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
[-] 2008-08-14 09:33 2023936 8206B5F94A6A9450E934029420C1693F c:\windows\$NtUninstallKB956572$\ntkrnlpa.exe
[-] 2008-04-13 18:31 2023936 7F653A89F6E89E3AE0D49830EECE35D4 c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
[-] 2004-08-03 23:05 2015232 FB142B7007CA2EEA76966C6C5CC12150 c:\windows\$NtUninstallKB956841_0$\ntkrnlpa.exe
[-] 2009-02-07 16:02 2066048 5BA7F2141BC6DB06100D0E5A732C617A c:\windows\Driver Cache\i386\ntkrnlpa.exe
[-] 2008-04-13 18:31 2065792 109F8E3E3C82E337BB71B6BC9B895D61 c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
[-] 2009-02-06 10:32 2023936 65D4220799E6FC2CB079070A6393CC0E c:\windows\system32\ntkrnlpa.exe
[-] 2009-02-07 16:02 2066048 5BA7F2141BC6DB06100D0E5A732C617A c:\windows\system32\dllcache\ntkrnlpa.exe
[-] 2009-02-07 16:35 2189184 EFE8EACE83EAAD5849A7A548FB75B584 c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[-] 2008-08-14 09:57 2185984 CE69DBD54221F2D40E49FF6DB77C6507 c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
[-] 2008-08-14 10:11 2189184 EEAF32F8E15A24F62BECB1BD403BB5C5 c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
[-] 2008-08-14 13:11 2189184 31914172342BFF330063F343AC6958FE c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
[-] 2008-08-14 09:58 2136064 DD31AB4B91C2605601A3C108AF57A0C9 c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
[-] 2008-08-14 10:09 2145280 F6F8245B3A2E9CA834DD318E7AE0C6D0 c:\windows\$NtUninstallKB956572$\ntoskrnl.exe
[-] 2008-04-13 19:24 2145280 40F8880122A030A7E9E1FEDEA833B33D c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
[-] 2004-08-03 21:18 2148352 626309040459C3915997EF98EC1C8D40 c:\windows\$NtUninstallKB956841_0$\ntoskrnl.exe
[-] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63F5212B c:\windows\Driver Cache\i386\ntoskrnl.exe
[-] 2008-04-13 19:27 2188928 0C89243C7C3EE199B96FCC16990E0679 c:\windows\ServicePackFiles\i386\ntoskrnl.exe
[-] 2009-02-06 11:06 2145280 0CBA44D0938D57F334C0862424148B70 c:\windows\system32\ntoskrnl.exe
[-] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63F5212B c:\windows\system32\dllcache\ntoskrnl.exe
[-] 2008-04-14 00:12 1033728 12896823FB95BFB3DC9B46BCAEDC9923 c:\windows\explorer.exe
[-] 2004-08-03 22:56 1032192 A0732187050030AE399B241436565E64 c:\windows\$NtServicePackUninstall$\explorer.exe
[-] 2008-04-14 00:12 1033728 12896823FB95BFB3DC9B46BCAEDC9923 c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2009-02-06 11:06 110592 020CEAAEDC8EB655B6506B8C70D53BB6 c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
[-] 2004-08-03 22:56 108032 C6CE6EEC82F187615D1002BB3BB50ED4 c:\windows\$NtServicePackUninstall$\services.exe
[-] 2008-04-14 00:12 108544 0E776ED5F7CC9F94299E70461B7B8185 c:\windows\$NtUninstallKB956572$\services.exe
[-] 2008-04-14 00:12 108544 0E776ED5F7CC9F94299E70461B7B8185 c:\windows\ServicePackFiles\i386\services.exe
[-] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225C37315 c:\windows\system32\services.exe
[-] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225C37315 c:\windows\system32\dllcache\services.exe
[-] 2004-08-03 22:56 13312 84885F9B82F4D55C6146EBF6065D75D2 c:\windows\$NtServicePackUninstall$\lsass.exe
[-] 2008-04-14 00:12 13312 BF2466B3E18E970D8A976FB95FC1CA85 c:\windows\ServicePackFiles\i386\lsass.exe
[-] 2008-04-14 00:12 13312 BF2466B3E18E970D8A976FB95FC1CA85 c:\windows\system32\lsass.exe
[-] 2004-08-03 22:56 15360 24232996A38C0B0CF151C2140AE29FC8 c:\windows\$NtServicePackUninstall$\ctfmon.exe
[-] 2008-04-14 00:12 15360 5F1D5F88303D4A4DBC8E5F97BA967CC3 c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2008-04-14 00:12 15360 5F1D5F88303D4A4DBC8E5F97BA967CC3 c:\windows\system32\ctfmon.exe
[-] 2004-08-03 22:56 57856 7435B108B935E42EA92CA94F59C8E717 c:\windows\$NtServicePackUninstall$\spoolsv.exe
[-] 2008-04-14 00:12 57856 D8E14A61ACC1D4A6CD0D38AEBAC7FA3B c:\windows\ServicePackFiles\i386\spoolsv.exe
[-] 2008-04-14 00:12 57856 D8E14A61ACC1D4A6CD0D38AEBAC7FA3B c:\windows\system32\spoolsv.exe
[-] 2004-08-03 22:56 24576 39B1FFB03C2296323832ACBAE50D2AFF c:\windows\$NtServicePackUninstall$\userinit.exe
[-] 2008-04-14 00:12 26112 A93AEE1928A9D7CE3E16D24EC7380F89 c:\windows\ServicePackFiles\i386\userinit.exe
[-] 2008-04-14 00:12 26112 A93AEE1928A9D7CE3E16D24EC7380F89 c:\windows\system32\userinit.exe
[-] 2004-08-03 22:56 295424 B60C877D16D9C880B952FDA04ADF16E6 c:\windows\$NtServicePackUninstall$\termsrv.dll
[-] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684B3479F c:\windows\ServicePackFiles\i386\termsrv.dll
[-] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684B3479F c:\windows\system32\termsrv.dll
[-] 2009-03-21 13:59 991744 DA11D9D6ECBDF0F93436A4B7C13F7BEC c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[-] 2004-08-03 22:56 983552 888190E31455FAD793312F8D087146EB c:\windows\$NtServicePackUninstall$\kernel32.dll
[-] 2008-04-14 00:11 989696 C24B983D211C34DA8FCC1AC38477971D c:\windows\$NtUninstallKB959426$\kernel32.dll
[-] 2008-04-14 00:11 989696 C24B983D211C34DA8FCC1AC38477971D c:\windows\ServicePackFiles\i386\kernel32.dll
[-] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBBBE95F3 c:\windows\system32\kernel32.dll
[-] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBBBE95F3 c:\windows\system32\dllcache\kernel32.dll
[-] 2004-08-03 22:56 17408 1B5F6923ABB450692E9FE0672C897AED c:\windows\$NtServicePackUninstall$\powrprof.dll
[-] 2008-04-14 00:12 17408 50A166237A0FA771261275A405646CC0 c:\windows\ServicePackFiles\i386\powrprof.dll
[-] 2008-04-14 00:12 17408 50A166237A0FA771261275A405646CC0 c:\windows\system32\powrprof.dll
[-] 2004-08-03 22:56 110080 87CA7CE6469577F059297B9D6556D66D c:\windows\$NtServicePackUninstall$\imm32.dll
[-] 2008-04-14 00:11 110080 0DA85218E92526972A821587E6A8BF8F c:\windows\ServicePackFiles\i386\imm32.dll
[-] 2008-04-14 00:11 110080 0DA85218E92526972A821587E6A8BF8F c:\windows\system32\imm32.dll
[-] 2004-08-03 22:56 1580544 30A609E00BD1D4FFC49D6B5A432BE7F2 c:\windows\$NtServicePackUninstall$\sfcfiles.dll
[-] 2008-04-14 00:12 1614848 9DD07AF82244867CA36681EA2D29CE79 c:\windows\ServicePackFiles\i386\sfcfiles.dll
[-] 2008-04-14 00:12 1614848 9DD07AF82244867CA36681EA2D29CE79 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-07-20 593920]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-12-21 53248]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-11-11 1236992]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 995328]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 1101824]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-06 198160]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-10-30 304664]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-11-28 244512]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-04-09 2029640]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-11-06 16855552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-1-17 618557]
REALTEK RTL8187 Wireless LAN Utility.lnk - c:\program files\Realtek\RTL8187 Wireless LAN Utility\RtWLan.exe [2009-2-22 815104]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
S1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [09/04/2009 03:18 م 107256]
S2 BandLuxe_Service;BandLuxe Service;c:\program files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe [03/10/2008 10:41 ص 87264]
S2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [22/02/2009 09:34 م 38144]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [09/04/2009 03:19 م 731840]
S2 gupdate1c9a3dace515bea;Google Update Service (gupdate1c9a3dace515bea);c:\program files\Google\Update\GoogleUpdate.exe [13/03/2009 03:54 م 133104]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\drivers\br3gmdm.sys [14/05/2009 03:30 ص 104192]
S3 lv321av;Logitech USB PC Camera (VC0321);c:\windows\system32\drivers\lv321av.sys [22/02/2009 04:46 م 847392]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [24/01/2009 02:46 م 216232]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [27/03/2009 10:48 م 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [27/03/2009 10:48 م 8320]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [22/02/2009 09:34 م 332928]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MDMXSDK
*NewlyCreated* - PARPORT
.
Contents of the 'Scheduled Tasks' folder
2009-05-22 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-13 12:54]
2009-05-22 c:\windows\Tasks\User_Feed_Synchronization-{255EB807-ACBB-453A-BBA1-5BF8C62AEDD1}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 15:36]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-INPROCOMMWireless - c:\program files\Atheros\Wireless\Utility\WlanUtil.exe
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.googel.com/
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-22 18:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1757981266-602162358-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*t*t* \OpenWithList]
@Class="Shell"
"a"="msnmsgr.exe"
"MRUList"="a"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4fb99b55-3ce3-4019-8ed9-061819cb59b1}]
@Denied: (Full) (Everyone)
"Model"=dword:0000007a
"Therad"=dword:0000000f
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):65,d3,a8,e6,cd,fc,f4,79,f3,15,0a,39,49,93,ff,32,b0,4a,ff,82,5b,
4d,e8,6d,f0,e8,39,49,64,58,d2,38,d2,f7,5c,21,48,2e,f3,7e,00,00,00,00,00,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(228)
c:\windows\System32\BCMLogon.dll
c:\windows\system32\netprovcredman.dll
- - - - - - - > 'explorer.exe'(1472)
c:\windows\system32\netprovcredman.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
Completion time: 2009-05-22 18:37
ComboFix-quarantined-files.txt 2009-05-22 15:37
Pre-Run: 28,671,524,864 bytes free
Post-Run: 28,676,784,128 bytes free
328 --- E O F --- 2009-03-10 22:04