ComboFix 09-06-08.05 - عزووز 06/09/2009 17:32.1 - NTFSx86
Running from: c:\documents and settings\عزووز\Desktop\New Folder\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
c:\windows\system32\vbscript.dll is missing
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\_004551_.tmp.dll
c:\windows\system32\_004552_.tmp.dll
c:\windows\system32\_004553_.tmp.dll
c:\windows\system32\_004554_.tmp.dll
c:\windows\system32\_004561_.tmp.dll
c:\windows\system32\_004563_.tmp.dll
c:\windows\system32\_004564_.tmp.dll
c:\windows\system32\_004566_.tmp.dll
c:\windows\system32\_004567_.tmp.dll
c:\windows\system32\_004570_.tmp.dll
c:\windows\system32\_004571_.tmp.dll
c:\windows\system32\_004573_.tmp.dll
c:\windows\system32\_004574_.tmp.dll
c:\windows\system32\_004575_.tmp.dll
c:\windows\system32\_004577_.tmp.dll
c:\windows\system32\_004580_.tmp.dll
c:\windows\system32\_004581_.tmp.dll
c:\windows\system32\_004585_.tmp.dll
c:\windows\system32\_004586_.tmp.dll
c:\windows\system32\_004588_.tmp.dll
c:\windows\system32\_004591_.tmp.dll
c:\windows\system32\_004593_.tmp.dll
c:\windows\system32\_004595_.tmp.dll
c:\windows\system32\_004596_.tmp.dll
c:\windows\system32\_004597_.tmp.dll
c:\windows\system32\_004600_.tmp.dll
c:\windows\system32\_004601_.tmp.dll
c:\windows\system32\_004602_.tmp.dll
c:\windows\system32\_004603_.tmp.dll
c:\windows\system32\_004604_.tmp.dll
c:\windows\system32\_004609_.tmp.dll
c:\windows\system32\_004611_.tmp.dll
c:\windows\system32\rpcss(2).dll
c:\windows\system32\Vxdif.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-09 to 2009-06-09 )))))))))))))))))))))))))))))))
.
2009-11-27 13:20 . 2008-09-12 10:44 206256 ----a-w- c:\windows\system32\idmmbc.dll
2009-06-06 18:46 . 2009-06-06 18:46 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-06-06 18:39 . 2009-06-06 18:39 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-06 17:53 . 2009-06-06 18:45 -------- d-----w- c:\documents and settings\Administrator.AL-AED01C4047E4\Local Settings\Application Data\Microsoft
2009-06-06 17:53 . 2009-06-06 18:45 -------- d-s---w- c:\documents and settings\Administrator.AL-AED01C4047E4
2009-05-18 19:34 . 2009-05-18 19:34 -------- d-----w- c:\documents and settings\عزووز\Local Settings\Application Data\ESET
2009-05-18 10:57 . 2009-05-18 10:57 -------- d-----w- c:\documents and settings\عزووز\Application Data\Media Player Classic
2009-05-17 02:12 . 2009-06-06 18:45 -------- d-----w- c:\documents and settings\عزووز\UserData
2009-05-16 01:39 . 2004-08-03 19:29 73216 ------w- c:\windows\system32\drivers\atintuxx.sys
2009-05-15 21:35 . 2008-04-13 18:46 273024 ----a-w- c:\windows\system32\drivers\bthport.sys
2009-05-15 20:45 . 2009-05-15 20:45 -------- d-----w- c:\documents and settings\عزووز\Application Data\ESET
2009-05-15 08:44 . 2009-05-15 08:44 -------- d-----w- c:\program files\ESET
2009-05-15 08:44 . 2009-05-15 08:44 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\ESET
2009-05-15 08:35 . 2009-05-15 08:35 -------- d--h--w- c:\windows\PIF
2009-05-15 07:58 . 2009-05-15 07:58 -------- d-----w- c:\documents and settings\عزووز\Local Settings\Application Data\Mozilla
2009-05-15 07:50 . 2009-05-15 07:50 165296 ----a-w- c:\documents and settings\عزووز\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
2009-05-15 07:50 . 2009-01-07 01:57 -------- d-----w- c:\documents and settings\عزووز\Application Data\IDM
2009-05-15 07:50 . 2009-06-09 14:33 -------- d-----w- c:\documents and settings\عزووز\Application Data\DMCache
2009-05-15 07:50 . 2009-05-15 07:50 -------- d-----w- c:\program files\Internet Download Manager
2009-05-15 07:49 . 2004-08-04 12:00 25600 ----a-w- c:\documents and settings\LocalService.NT AUTHORITY\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-05-15 07:46 . 2009-05-15 07:46 -------- d-----w- c:\windows\system32\LogFiles
2009-05-15 07:46 . 2007-08-10 17:46 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2009-05-15 07:05 . 2009-05-15 07:05 -------- d-----w- c:\windows\system32\wbem\MUI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 14:42 . 2003-12-31 21:53 3021269 ----a-r- C:\ComboFix.exe
2009-06-06 18:21 . 2003-12-31 22:37 -------- d-----w- c:\program files\Windows Live
2009-05-15 07:56 . 2009-05-15 07:56 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-04-09 12:21 . 2009-04-09 12:21 55768 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2009-04-09 12:21 . 2009-04-09 12:21 33096 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2009-04-09 12:21 . 2009-04-09 12:21 133000 ----a-w- c:\windows\system32\drivers\epfw.sys
2009-04-09 12:18 . 2009-04-09 12:18 107256 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-04-09 12:10 . 2009-04-09 12:10 113960 ----a-w- c:\windows\system32\drivers\eamon.sys
2009-03-21 14:06 . 2004-08-04 12:00 989696 ----a-w- c:\windows\system32\kernel32(2).dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-11-25 935856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-04-09 2029640]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2004-06-06 184320]
"ProgramPath"="c:\program files\Power Manager\PM.exe" [2004-09-28 155648]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-08-01 68096]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-06 88363]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-04-09 107256]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-04-09 731840]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - WINIO
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
HKLM-Run-VTTimer - VTTimer.exe
HKLM-Run-VTTrayp - VTtrayp.exe
HKLM-Run-Apoint - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-09 17:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):f9,f2,00,f8,c9,3a,45,fd,95,b6,d6,91,b3,e5,2b,25,84,86,f0,ed,46,
86,27,2f,56,fb,5c,0c,c3,b9,13,55,88,b7,78,44,88,1a,f8,41,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ece78318-0240-4d1e-bb7d-42827fac2747}]
@Denied: (Full) (Everyone)
"Model"=dword:0000016c
"Therad"=dword:00000016
.
Completion time: 2009-06-09 17:38
ComboFix-quarantined-files.txt 2009-06-09 14:38
Pre-Run: 6,468,100,096 bytes free
Post-Run: 6,448,148,480 bytes free
154 --- E O F --- 2009-05-18 12:56
( هل هذا هو المطلوب اخي الكريم ؟؟ )