سويت نفس الطريقة طلعلي بحث
هذا هو
ComboFix 09-05-31.02 - user 06/01/2009 0:26.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.20.1025.18.2039.1506 [GMT 3:00]
Running from: c:\documents and settings\user\سطح المكتب\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\kakle.dll
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
c:\windows\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-31 )))))))))))))))))))))))))))))))
.
2009-05-31 18:34 . 2009-05-31 18:34 -------- d-----w- c:\program files\Trend Micro
2009-05-30 22:09 . 2009-05-31 19:45 -------- d-----w- c:\program files\SpeedFan
2009-05-29 20:16 . 2009-05-29 20:16 -------- d-----w- c:\program files\ESET
2009-05-29 20:16 . 2009-05-29 20:16 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-05-29 19:29 . 2009-05-29 19:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-05-26 20:42 . 2009-05-27 20:59 -------- d-----w- c:\documents and settings\All Users\سطح المكتب
2009-05-26 20:41 . 2008-04-15 10:00 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-05-26 17:58 . 2009-05-26 17:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-05-26 17:50 . 2009-05-26 17:50 -------- d-----w- c:\documents and settings\All Users\قائمة ابدأ
2009-05-26 17:50 . 2009-05-26 17:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-05-26 16:15 . 2009-05-26 20:42 -------- d-----w- c:\documents and settings\All Users
2009-05-24 20:08 . 2009-05-24 20:08 -------- d-----w- c:\program files\directx
2009-05-24 20:08 . 2009-05-26 17:48 -------- d-----w- c:\program files\SeeMePlayMe
2009-05-24 20:07 . 2009-05-26 17:49 -------- d-----w- c:\program files\GameSpy Arcade
2009-05-24 20:04 . 2009-05-24 20:07 -------- d-----w- c:\program files\America's Army
2009-05-23 12:49 . 2009-05-23 12:49 -------- d-----w- c:\program files\MSXML 4.0
2009-05-22 23:03 . 2009-05-22 23:03 -------- d-----w- c:\windows\system32\KB905474
2009-05-22 23:03 . 2009-03-10 19:26 1430400 ----a-w- c:\windows\system32\KB905474\wganotifypackageinner.exe
2009-05-22 23:03 . 2009-03-10 19:18 453000 ----a-w- c:\windows\system32\KB905474\wgasetup.exe
2009-05-22 22:54 . 2008-04-15 10:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-05-22 22:34 . 2008-03-21 10:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-05-22 22:31 . 2009-03-19 10:48 8320 ----a-w- c:\windows\system32\drivers\nmwcdnsuc.sys
2009-05-22 22:31 . 2009-03-19 10:48 136704 ----a-w- c:\windows\system32\drivers\nmwcdnsu.sys
2009-05-22 22:31 . 2009-02-09 04:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-05-22 22:31 . 2009-02-09 04:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-05-22 22:31 . 2009-02-09 04:37 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2009-05-22 22:31 . 2009-02-09 04:37 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll
2009-05-22 22:31 . 2009-02-09 04:37 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2009-05-22 22:31 . 2009-02-09 04:32 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2009-05-22 22:26 . 2008-04-13 21:15 26112 ----a-w- c:\windows\system32\drivers\usbser.sys
2009-05-22 22:17 . 2009-05-22 22:17 -------- d-----w- c:\program files\MSXML 6.0
2009-05-22 22:16 . 2009-05-22 22:21 -------- d-----w- c:\documents and settings\user\Application Data\Nokia
2009-05-22 22:16 . 2009-05-22 22:16 -------- d-----w- c:\windows\Globalization
2009-05-22 22:15 . 2009-05-22 22:29 -------- d-----w- c:\program files\Common Files\Nokia
2009-05-22 22:14 . 2009-05-22 22:14 -------- d-----w- c:\program files\Common Files\PCSuite
2009-05-22 22:13 . 2009-05-22 22:13 -------- d-----w- c:\program files\DIFX
2009-05-22 22:13 . 2007-09-17 11:53 21632 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-05-22 22:13 . 2009-05-22 22:16 -------- d-----w- c:\documents and settings\user\Application Data\PC Suite
2009-05-22 22:12 . 2009-05-22 22:30 -------- d-----w- c:\program files\Nokia
2009-05-22 22:12 . 2009-02-09 04:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-05-22 22:05 . 2009-05-22 22:05 -------- d-----w- c:\program files\MSBuild
2009-05-22 22:05 . 2009-05-22 22:22 192240 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-22 22:00 . 2009-05-22 22:09 -------- d-----w- c:\windows\system32\XPSViewer
2009-05-22 21:59 . 2009-05-22 21:59 -------- d-----w- c:\program files\Reference Assemblies
2009-05-22 21:59 . 2006-06-29 10:07 14048 ------w- c:\windows\system32\spmsg2.dll
2009-05-22 20:38 . 2009-05-22 20:38 -------- d-----w- c:\windows\system32\LogFiles
2009-05-22 18:16 . 2009-05-22 18:16 -------- d-----w- c:\program files\CCleaner
2009-05-22 16:07 . 2008-06-14 17:31 271616 ------w- c:\windows\system32\dllcache\bthport.sys
2009-05-22 16:04 . 2008-05-08 14:02 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2009-05-22 16:03 . 2008-10-24 11:21 455296 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2009-05-22 16:03 . 2008-12-11 10:57 333952 ------w- c:\windows\system32\dllcache\srv.sys
2009-05-22 16:03 . 2008-05-01 14:34 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2009-05-22 16:03 . 2008-04-11 19:04 691712 ------w- c:\windows\system32\dllcache\inetcomm.dll
2009-05-22 15:57 . 2008-10-03 10:03 247326 ------w- c:\windows\system32\dllcache\strmdll.dll
2009-05-22 15:57 . 2008-10-15 16:35 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2009-05-22 15:57 . 2008-09-04 17:15 1106944 ------w- c:\windows\system32\dllcache\msxml3.dll
2009-05-22 15:55 . 2008-04-21 21:14 215040 ------w- c:\windows\system32\dllcache\wordpad.exe
2009-05-21 21:53 . 2009-05-21 21:53 -------- d-----w- c:\windows\Sun
2009-05-21 21:05 . 2008-10-16 11:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-05-21 21:05 . 2008-10-16 11:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-05-21 20:55 . 2009-05-21 20:55 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-05-21 20:52 . 2009-05-21 20:52 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-05-21 20:09 . 2009-05-29 21:06 -------- d-----w- c:\documents and settings\user\Tracing
2009-05-21 20:04 . 2009-05-21 20:04 -------- d-----w- c:\program files\Microsoft
2009-05-21 20:03 . 2009-05-21 20:03 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-05-21 20:01 . 2009-05-21 20:01 -------- d-----w- c:\program files\Common Files\Windows Live
2009-05-21 17:00 . 2009-05-21 16:59 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-21 16:59 . 2009-05-21 16:59 152576 ----a-w- c:\documents and settings\user\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-14 20:45 . 2009-05-14 20:45 -------- d-----w- c:\program files\ProgDVBStd
2009-05-14 20:45 . 2009-05-14 20:45 -------- d-----w- C:\Offline Download
2009-05-14 20:45 . 2009-05-14 20:45 -------- d-----w- C:\Video Center
2009-05-14 20:45 . 2009-05-14 20:45 -------- d-----w- c:\program files\ProgEdit
2009-05-14 20:45 . 2009-05-14 20:45 -------- d-----w- c:\windows\system32\Codec
2009-05-14 20:45 . 2009-05-14 20:45 -------- d-----w- c:\program files\IGI Subtitler
2009-05-14 20:45 . 2009-05-14 20:45 -------- d-----w- c:\program files\vPlug Files Center
2009-05-14 20:42 . 2009-05-14 20:45 -------- d-----w- c:\program files\ProgDVB
2009-05-14 20:42 . 2009-05-14 20:45 -------- d-----w- c:\program files\DVB-S PowerInstall
2009-05-14 20:26 . 2009-05-14 20:26 -------- d-----w- c:\windows\AltDVB Sat4all Edition
2009-05-14 19:25 . 2009-05-14 20:06 -------- d-----w- C:\ProgDVB
2009-05-13 15:56 . 2008-04-13 21:21 101120 ----a-w- c:\windows\system32\drivers\bthpan.sys
2009-05-13 15:56 . 2008-04-13 21:16 59136 ----a-w- c:\windows\system32\drivers\rfcomm.sys
2009-05-13 15:56 . 2008-04-13 21:16 17024 ----a-w- c:\windows\system32\drivers\BthEnum.sys
2009-05-13 15:56 . 2008-04-14 18:29 8192 ----a-w- c:\windows\system32\wshirda.dll
2009-05-13 15:56 . 2008-04-14 18:29 151040 ----a-w- c:\windows\system32\irftp.exe
2009-05-13 15:56 . 2008-04-14 18:29 27648 ----a-w- c:\windows\system32\irmon.dll
2009-05-13 15:55 . 2008-06-14 17:31 271616 ----a-w- c:\windows\system32\drivers\bthport.sys
2009-05-13 15:55 . 2008-04-13 21:16 18944 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2009-05-09 12:54 . 2008-10-16 11:09 43544 ----a-w- c:\windows\system32\wups2.dll
2009-05-07 22:05 . 2008-04-13 21:09 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2009-05-07 22:05 . 2008-04-13 21:16 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2009-05-07 22:05 . 2008-04-13 21:16 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2009-05-07 22:05 . 2008-04-13 21:16 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2009-05-07 22:05 . 2008-04-13 21:16 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2009-05-07 22:05 . 2008-04-13 21:16 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2009-05-07 22:05 . 2008-04-13 21:16 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2009-05-07 22:04 . 2008-04-14 18:29 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2009-05-07 22:04 . 2009-05-22 18:13 -------- d-----w- c:\program files\ManyCam 2.4
2009-05-07 22:04 . 2009-05-07 22:05 -------- d-----w- c:\documents and settings\user\Application Data\ManyCam
2009-05-05 21:31 . 2009-05-05 21:31 -------- d-----w- c:\program files\TechSmith
2009-05-05 21:31 . 2009-05-05 21:31 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\TechSmith
2009-05-05 21:24 . 2009-05-05 21:24 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-31 21:32 . 2009-04-21 13:01 -------- d-----w- c:\documents and settings\user\Application Data\DMCache
2009-05-31 20:53 . 2008-04-15 10:00 67686 ----a-w- c:\windows\system32\perfc001.dat
2009-05-31 20:53 . 2008-04-15 10:00 367298 ----a-w- c:\windows\system32\perfh001.dat
2009-05-30 22:09 . 2009-04-21 13:01 -------- d-----w- c:\documents and settings\user\Application Data\IDM
2009-05-23 21:41 . 2009-04-21 12:58 95216 ----a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-22 22:56 . 2009-04-21 11:32 -------- d-----w- c:\program files\Microsoft Works
2009-05-22 22:34 . 2009-05-22 22:34 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-05-22 22:34 . 2009-05-22 22:34 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-05-22 22:25 . 2009-05-22 22:25 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2009-05-22 22:25 . 2009-05-22 22:25 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-05-22 18:13 . 2009-04-21 11:43 -------- d-----w- c:\program files\Paltalk Messenger
2009-05-22 18:13 . 2009-04-21 10:52 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-22 18:13 . 2009-04-21 11:43 -------- d-----w- c:\program files\JetAudio
2009-05-21 20:04 . 2009-04-21 11:01 -------- d-----w- c:\program files\Windows Live
2009-05-21 16:59 . 2009-04-21 11:04 -------- d-----w- c:\program files\Java
2009-05-14 20:49 . 2009-04-22 00:52 -------- d-----w- c:\program files\Common Files\Elecard
2009-05-01 07:27 . 2009-05-01 07:27 -------- d-----w- c:\documents and settings\user\Application Data\TopLang
2009-04-29 00:38 . 2009-04-29 00:31 -------- d-----w- c:\documents and settings\user\Application Data\uTorrent
2009-04-29 00:31 . 2009-04-29 00:31 -------- d-----w- c:\program files\AskBarDis
2009-04-29 00:31 . 2009-04-29 00:31 -------- d-----w- c:\program files\uTorrent
2009-04-25 21:31 . 2009-04-21 12:51 -------- d-----w- c:\program files\Golden Al-Wafi Translator
2009-04-22 16:42 . 2009-04-21 11:40 -------- d-----w- c:\documents and settings\user\Application Data\BSplayer PRO
2009-04-22 01:00 . 2009-04-22 01:00 -------- d-----w- c:\documents and settings\user\Application Data\Media Player Classic
2009-04-22 00:52 . 2009-04-22 00:52 -------- d-----w- c:\program files\Elecard
2009-04-22 00:33 . 2009-04-22 00:33 -------- d-----w- c:\program files\DVBViewerTE
2009-04-22 00:33 . 2009-04-22 00:32 -------- d-----w- c:\program files\TechniSat DVB
2009-04-22 00:32 . 2009-04-22 00:32 -------- d-----w- c:\program files\MainConcept
2009-04-22 00:32 . 2009-04-21 11:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-04-21 22:11 . 2009-04-21 11:17 -------- d-----w- c:\program files\Common Files\InstallShield
2009-04-21 13:01 . 2009-04-21 13:01 120240 ----a-w- c:\documents and settings\user\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
2009-04-21 13:00 . 2009-04-21 13:00 0 ----a-w- c:\windows\nsreg.dat
2009-04-21 12:59 . 2009-04-21 12:59 -------- d-----w- c:\program files\Messenger Plus! Live
2009-04-21 12:54 . 2009-04-21 11:41 1245184 ----a-w- c:\windows\system32\bkll.dll
2009-04-21 12:54 . 2009-04-21 11:41 2846720 ----a-w- c:\windows\system32\agsaamj.dll
2009-04-21 12:54 . 2009-04-21 11:41 215552 ----a-w- c:\windows\system32\ALOWMVFile.dll
2009-04-21 12:54 . 2009-04-21 11:41 90112 ----a-w- c:\windows\system32\agsaami.dll
2009-04-21 12:54 . 2009-04-21 11:41 403968 ----a-w- c:\windows\system32\ALOWMAFile2.dll
2009-04-21 12:54 . 2009-04-21 11:41 188416 ----a-w- c:\windows\system32\ALOVideoFile.dll
2009-04-21 12:54 . 2009-04-21 11:41 626688 ----a-w- c:\windows\system32\agsaamh.dll
2009-04-21 12:54 . 2009-04-21 11:41 753664 ----a-w- c:\windows\system32\agsaamg.dll
2009-04-21 12:54 . 2009-04-21 11:41 495104 ----a-w- c:\windows\system32\ALOVideoCoreM.dll
2009-04-21 12:50 . 2009-04-21 12:50 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-04-21 12:50 . 2009-04-21 12:50 172032 ------w- c:\windows\Setup1.exe
2009-04-21 12:44 . 2009-04-21 11:44 -------- d-----w- c:\documents and settings\user\Application Data\Skype
2009-04-21 12:13 . 2009-04-21 12:13 -------- d-----w- c:\program files\CONEXANT
2009-04-21 12:12 . 2009-04-21 12:12 -------- d-----w- c:\documents and settings\user\Application Data\ESET
2009-04-21 11:47 . 2009-04-21 11:06 -------- d-----w- c:\program files\Common Files\Adobe
2009-04-21 11:45 . 2009-04-21 11:45 -------- d-----w- c:\program files\Common Files\xing shared
2009-04-21 11:45 . 2009-04-21 11:45 -------- d-----w- c:\program files\Real
2009-04-21 11:45 . 2009-04-21 11:45 -------- d-----w- c:\program files\Common Files\Real
2009-04-21 11:44 . 2009-04-21 11:05 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-04-21 11:43 . 2009-04-21 11:43 -------- d-----w- c:\program files\Skype
2009-04-21 11:43 . 2009-04-21 11:43 -------- d-----w- c:\program files\Common Files\Skype
2009-04-21 11:43 . 2009-04-21 11:43 -------- d-----w- c:\documents and settings\user\Application Data\Paltalk
2009-04-21 11:43 . 2009-04-21 11:43 -------- d-----w- c:\documents and settings\user\Application Data\COWON
2009-04-21 11:42 . 2009-04-21 11:42 -------- d-----w- c:\program files\DivX
2009-04-21 11:42 . 2009-04-21 11:42 2232 ----a-w- c:\windows\java\Packages\Data\RB17735N.DAT
2009-04-21 11:42 . 2009-04-21 11:42 155995 ----a-w- c:\windows\java\Packages\TVFJFJLF.ZIP
2009-04-21 11:42 . 2009-04-21 11:42 2678 ----a-w- c:\windows\java\Packages\Data\KB7VPZ79.DAT
2009-04-21 11:42 . 2009-04-21 11:42 2678 ----a-w- c:\windows\java\Packages\Data\XZDNH3ZN.DAT
2009-04-21 11:42 . 2009-04-21 11:42 2678 ----a-w- c:\windows\java\Packages\Data\XBHVBX7J.DAT
2009-04-21 11:42 . 2009-04-21 11:42 2678 ----a-w- c:\windows\java\Packages\Data\NXVN7NNF.DAT
2009-04-21 11:42 . 2009-04-21 11:42 2678 ----a-w- c:\windows\java\Packages\Data\LRN1FTNJ.DAT
2009-04-21 11:40 . 2009-04-21 11:40 -------- d-----w- c:\program files\Ozone
2009-04-21 11:40 . 2009-04-21 11:40 -------- d-----w- c:\program files\Webteh
2009-04-21 11:31 . 2009-04-21 11:31 -------- d-----w- c:\program files\Microsoft.NET
2009-04-21 11:17 . 2009-04-21 11:17 -------- d-----w- c:\program files\Realtek
2009-04-21 11:17 . 2009-04-21 11:17 -------- d-----w- c:\documents and settings\user\Application Data\InstallShield
2009-04-21 11:12 . 2009-04-21 11:12 -------- d-----w- c:\program files\Intel
2009-04-21 11:06 . 2009-04-21 11:06 -------- d-----w- c:\program files\Vista Drive Icon
2009-04-21 11:05 . 2009-04-21 11:05 -------- d-----w- c:\program files\UltraISO
2009-04-21 11:05 . 2009-04-21 11:05 -------- d-----w- c:\program files\Common Files\EZB Systems
2009-04-21 11:04 . 2009-04-21 11:04 -------- d-----w- c:\program files\Common Files\Java
2009-04-21 11:01 . 2009-04-21 11:01 -------- d-----w- c:\program files\Internet Download Manager
2009-04-21 10:55 . 2009-04-21 10:55 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-21 10:52 . 2009-04-21 10:52 22144 ----a-w- c:\windows\system32\emptyregdb.dat
2009-04-09 12:21 . 2009-04-09 12:21 55768 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2009-04-09 12:21 . 2009-04-09 12:21 33096 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2009-04-09 12:21 . 2009-04-09 12:21 133000 ----a-w- c:\windows\system32\drivers\epfw.sys
2009-04-09 12:18 . 2009-04-09 12:18 107256 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-04-09 12:10 . 2009-04-09 12:10 113960 ----a-w- c:\windows\system32\drivers\eamon.sys
2009-03-30 04:25 . 2009-03-30 04:25 94208 ----a-w- c:\windows\system32\TLDL.DLL
2009-03-28 01:40 . 2009-03-28 01:40 18030 ----a-w- c:\windows\system32\drivers\DeskLock.sys
2009-03-08 02:34 . 2008-12-07 22:16 914944 ----a-w- c:\windows\system32\wininet.dll
2009-03-08 02:34 . 2008-04-15 10:00 43008 ----a-w- c:\windows\system32\licmgr10.dll
2009-03-08 02:33 . 2008-04-15 10:00 18944 ----a-w- c:\windows\system32\corpol.dll
2009-03-08 02:33 . 2008-04-15 10:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2009-03-08 02:32 . 2008-04-15 10:00 72704 ----a-w- c:\windows\system32\admparse.dll
2009-03-08 02:32 . 2008-04-15 10:00 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-03-08 02:31 . 2008-04-15 10:00 34816 ----a-w- c:\windows\system32\imgutil.dll
2009-03-08 02:31 . 2008-04-15 10:00 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-03-08 02:31 . 2008-04-15 10:00 45568 ----a-w- c:\windows\system32\mshta.exe
2009-03-08 02:22 . 2008-04-15 10:00 156160 ----a-w- c:\windows\system32\msls31.dll
2009-03-06 14:20 . 2008-04-15 10:00 283136 ----a-w- c:\windows\system32\pdh.dll
.
------- Sigcheck -------
[-] 2008-12-07 22:16 578048 0AEEDFCCDA0E5A5496B8E26E8D0D5930 c:\windows\system32\user32.dll
[-] 2008-12-11 20:58 1652224 76834B69857CB5CF48AC5F3C899B4B4E c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 10:47 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-09-15 2606512]
"ManyCam"="c:\program files\ManyCam 2.4\ManyCam.exe" [2009-04-17 1824040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-21 185896]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-04-09 2029640]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-11-14 16270848]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-15 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\America's Army\\System\\ArmyOps.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 ulsata2;ulsata2;c:\windows\system32\drivers\ulsata2.sys [07/12/2008 07:03 م 124928]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [09/04/2009 03:18 م 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [09/04/2009 03:19 م 731840]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [14/01/2008 01:06 م 21632]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\drivers\SkyNET.sys [22/04/2009 12:57 ص 510992]
S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [29/04/2009 03:32 ص 234888]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [23/05/2009 01:31 ص 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [23/05/2009 01:31 ص 8320]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [26/04/2009 01:27 ص 194304]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-05-25 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-05-31 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-05-31 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-22 19:18]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: إضافة إلى حاجب إعلان الشعار - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java -
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\ltckiu7y.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sa/
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=
FF - component: c:\documents and settings\user\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-01 00:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1396)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(1452)
c:\windows\system32\setupapi.dll
.
Completion time: 2009-05-31 0:34
ComboFix-quarantined-files.txt 2009-05-31 21:34
Pre-Run: 16,821,760,000 bytes free
Post-Run: 17,123,721,216 bytes free
334 --- E O F --- 2009-05-25 13:13