ComboFix 09-05-22.07 - Administrator 05/23/2009 15:02.5 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.607.297 [GMT 2:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
AV: AVG Internet Security *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
AV: Sunbelt VIPRE *On-access scanning disabled* (Updated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\tmp.reg
.
((((((((((((((((((((((((( Files Created from 2009-04-23 to 2009-05-23 )))))))))))))))))))))))))))))))
.
2009-05-23 12:51 . 2009-05-23 12:51 -------- d-----w c:\windows\LastGood
2009-05-23 12:36 . 2009-05-23 12:36 -------- d-----w C:\Temp
2009-05-23 12:20 . 2009-05-23 12:20 -------- d-----w c:\program files\Common Files\delet
2009-05-23 09:18 . 2009-05-23 09:18 -------- d-sh--w C:\FOUND.061
2009-05-22 19:31 . 2009-05-22 19:31 -------- d-----w c:\documents and settings\Administrator\Application Data\Auslogics
2009-05-22 18:52 . 2009-05-22 18:52 -------- d-----w c:\documents and settings\Administrator\Application Data\ESET
2009-05-22 18:47 . 2009-05-22 18:47 -------- d-----w c:\program files\CCleaner
2009-05-22 17:30 . 2009-05-22 17:30 -------- d-----w c:\program files\PhotoZoom Pro 2
2009-05-22 17:21 . 2009-05-22 17:21 198064 ----a-w c:\documents and settings\Administrator\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-05-22 16:56 . 2009-05-22 16:57 61440 ----a-w c:\windows\twmsico.dll
2009-05-22 16:32 . 2009-05-22 16:32 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-05-22 16:25 . 2009-05-22 16:25 -------- d-----w c:\program files\Common Files\Skype
2009-05-22 16:16 . 2009-05-22 16:16 -------- d-----w c:\windows\system32\Ads
2009-05-22 15:32 . 2009-05-22 15:32 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-05-22 12:13 . 2009-05-22 12:13 -------- d-----w c:\program files\ESET
2009-05-22 10:26 . 2009-05-22 10:26 -------- d-----w c:\program files\Your Uninstaller 2008
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-23 12:52 . 2009-05-22 18:11 4530 ----a-w c:\windows\system32\PerfStringBackup.TMP
2009-05-23 12:46 . 2009-05-23 12:39 4529160 ----a-w c:\documents and settings\Administrator\Application Data\IDM\DwnlData\Administrator\Zyzoom.org.McAfee_1342\Zyzoom.org.McAfee.exe
2009-05-06 19:34 . 2009-05-23 12:39 2173609 ----a-w c:\documents and settings\Administrator\Application Data\IDM\DwnlData\Administrator\Zyzoom.org.McAfee_1342\SmitfraudFix\SmitfraudFix.cmd
2009-04-29 23:36 . 2009-05-23 12:39 75776 ----a-w c:\documents and settings\Administrator\Application Data\IDM\DwnlData\Administrator\Zyzoom.org.McAfee_1342\SmitfraudFix\WS2Fix.exe
2009-04-04 21:52 . 2009-05-23 12:39 180224 ----a-w c:\documents and settings\Administrator\Application Data\IDM\DwnlData\Administrator\Zyzoom.org.McAfee_1342\SmitfraudFix\ProxyDisable.exe
2009-03-26 15:35 . 2009-01-13 11:13 210352 ----a-w c:\windows\system32\idmmbc.dll
2009-03-17 13:32 . 2009-03-17 13:32 44384 ----a-w c:\windows\system32\drivers\tifsfilt.sys
2009-03-17 13:32 . 2009-03-17 13:32 441760 ----a-w c:\windows\system32\drivers\timntr.sys
2009-03-17 13:31 . 2009-03-17 13:31 132224 ----a-w c:\windows\system32\drivers\snapman.sys
2009-03-17 13:30 . 2009-03-17 13:30 368480 ----a-w c:\windows\system32\drivers\tdrpman.sys
2009-03-16 12:41 . 2009-03-16 12:41 20480 ---h--w c:\documents and settings\Administrator\Application Data\shamela\60B4FC92\reporter.exe
2009-03-10 07:32 . 2009-03-10 07:32 40960 ----a-r c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{9B73034E-47B5-4870-B9E2-3F7A5AE3859A}\NewShortcut3_C74A9C274ADC40748849370F4FC8D3B6.exe
2009-03-10 07:32 . 2009-03-10 07:32 40960 ----a-r c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{9B73034E-47B5-4870-B9E2-3F7A5AE3859A}\NewShortcut1_C74A9C274ADC40748849370F4FC8D3B6_4.exe
2009-03-10 07:32 . 2009-03-10 07:32 10134 ----a-r c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{9B73034E-47B5-4870-B9E2-3F7A5AE3859A}\ARPPRODUCTICON.exe
2009-03-08 02:34 . 2004-08-03 20:55 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 02:34 . 2004-08-03 20:55 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 02:33 . 2004-08-03 20:55 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 02:33 . 2004-08-03 20:55 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 02:32 . 2004-08-03 20:55 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 02:32 . 2004-08-03 20:55 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 02:31 . 2004-08-03 20:55 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 02:31 . 2004-08-03 20:53 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 02:31 . 2004-08-03 20:56 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 02:22 . 2001-09-19 10:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-02 08:12 . 2009-03-02 08:12 58336 ---ha-w c:\windows\system32\mlfcache.dat
2009-02-27 14:45 . 2009-02-27 14:45 9728 ----a-w c:\windows\system32\BsMonUI.dll
2009-02-27 14:45 . 2009-02-27 14:45 18432 ----a-w c:\windows\system32\BsMonSvr.dll
2009-02-27 14:45 . 2009-02-27 14:45 405589 ----a-w c:\windows\system32\BsUI.dll
2009-02-27 14:45 . 2009-02-27 14:45 57430 ----a-w c:\windows\system32\btfunc.dll
2009-02-27 14:44 . 2009-02-27 14:44 278647 ----a-w c:\windows\system32\outlookAddin.dll
2009-02-27 14:44 . 2009-02-27 14:44 53248 ----a-w c:\windows\system32\HtmPrintHelper.dll
2009-02-27 14:44 . 2009-02-27 14:44 114774 ----a-w c:\windows\system32\versit.dll
2009-02-27 14:44 . 2009-02-27 14:44 622693 ----a-w c:\windows\system32\BSShell.dll
2009-02-27 14:43 . 2009-02-27 14:43 557142 ----a-w c:\windows\system32\Bscdlg.dll
2009-02-27 14:43 . 2009-02-27 14:43 114788 ----a-w c:\windows\system32\BsProfileFunc.dll
2009-02-27 14:43 . 2009-02-27 14:43 151642 ----a-w c:\windows\system32\BsCommon.dll
2009-02-27 14:43 . 2009-02-27 14:43 94314 ----a-w c:\windows\system32\BsHelpCSps.dll
2009-02-27 14:43 . 2009-02-27 14:43 553075 ----a-w c:\windows\system32\BlueSoleilCSps.dll
2009-02-27 14:41 . 2009-02-27 14:41 28766 ----a-w c:\windows\system32\PlayerCtrl.dll
2009-02-27 14:41 . 2009-02-27 14:41 241748 ----a-w c:\windows\system32\BsSDK.dll
2009-02-27 14:41 . 2009-02-27 14:41 122976 ----a-w c:\windows\system32\BsMobileSDK.dll
2009-02-27 14:40 . 2009-02-27 14:40 28672 ----a-w c:\windows\system32\BsMobileCSps.dll
2009-02-27 14:40 . 2009-02-27 14:40 28760 ----a-w c:\windows\system32\BsTrace.dll
2009-02-27 14:38 . 2009-02-27 14:38 110691 ----a-w c:\windows\system32\Bs2Res.dll
2009-02-26 11:43 . 2009-02-26 11:43 107888 ----a-w c:\windows\system32\CmdLineExt.dll
2009-02-06 10:25 . 2009-01-05 14:13 4543 ----a-w c:\program files\Common Files\unins000.dat
2009-02-06 10:22 . 2009-01-05 14:13 732113 ----a-w c:\program files\Common Files\unins000.exe
2008-03-09 05:25 . 2009-01-05 14:14 236 ---ha-w c:\program files\Common Files\dx.reg
.
(((((((((((((((((((((((((((((
SnapShot@2009-05-23_12.02.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-23 12:53 . 2009-05-14 13:49 55768 c:\windows\LastGood\system32\DRIVERS\epfwtdi.sys
+ 2009-05-23 12:52 . 2009-05-14 13:49 33096 c:\windows\LastGood\system32\DRIVERS\epfwndis.sys
+ 2009-05-23 12:53 . 2009-05-14 13:49 133000 c:\windows\LastGood\system32\DRIVERS\epfw.sys
+ 2009-05-23 12:53 . 2009-05-14 13:47 107256 c:\windows\LastGood\system32\DRIVERS\ehdrv.sys
+ 2009-05-23 12:53 . 2009-05-14 13:41 114472 c:\windows\LastGood\system32\DRIVERS\eamon.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Privacy Suite"="c:\documents and settings\Administrator\Application Data\cleaner\CSPSeraser.exe" [2007-11-20 872080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-15 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"HiChatter"=c:\program files\Beyluxe Messenger\Beyluxe Messenger.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BtTray"="c:\program files\IVT Corporation\BlueSoleil\BtTray.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP

oVoo TCP المنفذ 443
"443:UDP"= 443:UDP

oVoo UDP المنفذ 443
"37674:TCP"= 37674:TCP

oVoo TCP المنفذ 37674
"37674:UDP"= 37674:UDP

oVoo UDP المنفذ 37674
"37675:UDP"= 37675:UDP

oVoo UDP المنفذ 37675
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [2009-01-07 20744]
R1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys --> c:\windows\system32\DRIVERS\ehdrv.sys [?]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-02-03 43816]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [2008-12-07 30088]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [2008-07-02 26248]
S2 ousbehci;%OWC_USBEHCD.DeviceDesc%;c:\windows\system32\drivers\ousbehci.sys [2009-01-20 29568]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\DRIVERS\avgfwdx.sys --> c:\windows\system32\DRIVERS\avgfwdx.sys [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwdx.sys --> c:\windows\system32\DRIVERS\avgfwdx.sys [?]
S3 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - ALG
*Deregistered* - AudioSrv
*Deregistered* - BITS
*Deregistered* - BlueSoleilCS
*Deregistered* - Browser
*Deregistered* - BsHelpCS
*Deregistered* - BsMobileCS
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ekrn
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - helpsvc
*Deregistered* - ImapiService
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - MSIServer
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - RasMan
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - TapiSrv
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - TuneUp.ProgramStatisticsSvc
*Deregistered* - UxTuneUp
*Deregistered* - W32Time
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.fr/
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Add to AMV Convert Tool...
IE: E???? ??E?? ??I?? (??.??.??) EU ??E??E IC????I ?C????
IE: E???? C??? EU ??E??E IC????I ?C????
IE: E???? EU ??E??E IC????I ?C????
IE: Envoyer via Bluetooth - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
IE: Envoyer via message(&M)... - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
IE: MediaManager tool grab multimedia file
IE: Send to &Bluetooth Device...
IE: E???? ??E?? ??I?? (??.??.??) EU ??E??E IC????I ?C???? - c:\program files\Internet Download Manager\IEGetVL.htm
IE: E???? C??? EU ??E??E IC????I ?C???? - c:\program files\Internet Download Manager\IEGetAll.htm
IE: E???? EU ??E??E IC????I ?C???? - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
IE: {{000002a3-84fe-43f1-b958-f2c3ca804f1a} - {CD275D4E-791A-4993-9D4D-6A071EDD2709} - c:\program files\IEPro\iepro.dll
LSP: c:\windows\system32\idmmbc.dll
TCP: {C5DF7C60-6C69-48D6-B631-3E84290A03B4} = 208.67.222.222 208.67.220.220
FF - ProfilePath - c:\docume~1\ADMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\v54pt70m.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://ar.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:ar

fficial
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: content.notify.interval - 750000
FF - user.js: content.max.tokenizing.time - 2250000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-23 15:04
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1957994488-507921405-1060284298-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,0c,cd,69,1a,f1,d1,49,48,8f,b6,20,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3b,a0,41,b1,e4,62,7c,42,91,be,84,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3d3e27a9-2812-41ba-9128-02fa5d117f7d}]
@Denied: (Full) (Everyone)
"Model"=dword:0000002c
"Therad"=dword:0000000f
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d,
df,1c,2f,3b,8a,0a,32,11,89,01,b5,c5,12,99,a6,02,e9,10,be,a6,0a,cb,14,04,89,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):76,b2,53,cc,06,d7,03,d4,39,08,ae,49,f4,cb,3b,43,8e,e5,b0,6e,0a,
4d,5a,e3,73,ac,81,57,d9,60,26,ce,91,50,dc,71,ff,22,db,e2,00,00,00,00,00,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(944)
c:\windows\system32\idmmbc.dll
.
Completion time: 2009-05-23 15:06
ComboFix-quarantined-files.txt 2009-05-23 13:06
ComboFix2.txt 2009-05-23 12:05
Pre-Run: 9,861,955,584 bytes free
Post-Run: 9,860,710,400 bytes free
263 --- E O F --- 2009-05-22 13:31