هذا التقرير...اخي العزيز
ComboFix 09-08-02.03 - XPPRESP3 08/03/2009 10:02.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.2046.1590 [GMT 3:00]
Running from: c:\documents and settings\XPPRESP3\My Documents\Downloads\Programs\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\temp.temp
c:\windows\system32\msconfig.exe
c:\windows\system32\nvwrsfr.dll
c:\windows\system32\winio.vxd
.
((((((((((((((((((((((((( Files Created from 2009-07-03 to 2009-08-03 )))))))))))))))))))))))))))))))
.
2009-08-03 05:45 . 2009-08-03 05:45 -------- d-----w- c:\program files\Trend Micro
2009-08-02 20:14 . 2009-08-02 20:14 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\Gearbox Software
2009-08-02 19:58 . 2009-08-02 19:58 -------- d-----w- c:\program files\Ubisoft
2009-08-02 19:40 . 2009-08-02 19:40 -------- d-----w- c:\program files\Ninja Turtles
2009-08-02 19:13 . 2009-08-02 19:15 442003 ----a-w- c:\documents and settings\XPPRESP3\Application Data\IDM\DwnlData\XPPRESP3\directx_oct2006_redist_20\directx_oct2006_redist.exe
2009-08-02 18:46 . 2009-08-02 18:46 -------- d-----w- c:\windows\Sun
2009-08-02 10:52 . 2009-08-02 10:52 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\MiniDm
2009-08-02 10:11 . 2009-08-02 10:11 -------- d-----w- c:\program files\IEPro
2009-08-02 10:10 . 2009-08-02 10:10 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\IEPro
2009-08-02 10:04 . 2009-08-02 10:10 2487552 ----a-w- c:\documents and settings\XPPRESP3\Application Data\IE7Pro\prosetup.exe
2009-07-31 06:02 . 2009-07-31 06:02 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\ICAClient
2009-07-30 07:24 . 2009-07-30 07:24 -------- d-sh--w- c:\windows\ftpcache
2009-07-29 17:03 . 2009-07-29 17:03 -------- d-----w- c:\documents and settings\XPPRESP3\Local Settings\Application Data\TechSmith
2009-07-29 17:02 . 2008-07-10 10:56 107864 ----a-w- c:\windows\system32\tsccvid.dll
2009-07-29 17:02 . 2009-07-29 17:02 -------- d-----w- c:\windows\system32\QuickTime
2009-07-29 17:02 . 2009-07-29 17:02 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith
2009-07-29 17:01 . 2009-07-29 17:01 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2009-07-29 17:01 . 2009-07-29 17:01 -------- d-----w- c:\program files\TechSmith
2009-07-29 16:56 . 2009-07-29 16:56 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\Nokia Multimedia Player
2009-07-27 19:10 . 2009-07-27 19:10 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\fltk.org
2009-07-27 17:53 . 2009-08-02 10:02 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-07-27 17:50 . 2007-12-29 17:22 27776592 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{29466F9C-7C6A-419C-B301-F440FAF78760}\Nokia_PC_Suite_rel_6_85_14_1_ara.exe
2009-07-27 17:50 . 2009-07-27 17:50 733783 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{29466F9C-7C6A-419C-B301-F440FAF78760}\Packages\Nokia_PC_Suite\CustomActions\NSU_Inst_fix.exe
2009-07-27 17:50 . 2009-07-27 17:50 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{29466F9C-7C6A-419C-B301-F440FAF78760}\Installer\CommonCustomActions\UninstCCD.exe
2009-07-27 17:50 . 2009-07-27 17:50 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{29466F9C-7C6A-419C-B301-F440FAF78760}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-07-27 17:50 . 2009-07-27 17:50 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{29466F9C-7C6A-419C-B301-F440FAF78760}\Installer\CommonCustomActions\UninstPCS.exe
2009-07-27 17:50 . 2009-07-27 17:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-07-27 16:45 . 2009-07-27 16:45 -------- d-----w- c:\program files\VID_0E8F&PID_103F
2009-07-27 16:41 . 2001-08-17 10:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-07-27 16:41 . 2001-08-17 11:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-07-27 16:23 . 2009-07-27 16:23 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\CyberLink
2009-07-27 16:21 . 2006-10-26 16:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2009-07-27 16:20 . 2009-07-27 16:20 -------- d-----w- c:\program files\Microsoft Works
2009-07-27 16:20 . 2009-07-27 16:20 -------- d-----w- c:\program files\MSBuild
2009-07-27 16:19 . 2009-07-27 16:19 -------- d-----w- c:\program files\Microsoft.NET
2009-07-27 16:16 . 2009-07-27 16:16 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-07-27 16:16 . 2009-07-27 16:16 -------- d-----w- c:\windows\SHELLNEW
2009-07-27 16:15 . 2009-07-27 16:15 -------- d-----w- c:\documents and settings\XPPRESP3\Local Settings\Application Data\Microsoft Help
2009-07-27 16:15 . 2009-07-27 16:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-27 16:15 . 2009-07-27 16:15 -------- d--h--r- C:\MSOCache
2009-07-27 14:20 . 2009-07-27 14:20 -------- d-----w- c:\program files\UltraUXThemePatcher
2009-07-27 14:17 . 2009-07-27 14:20 -------- d-----w- c:\windows\VistaMizer
2009-07-27 14:00 . 2008-05-29 06:28 28416 ----a-w- c:\windows\system32\uxtuneup.dll
2009-07-27 14:00 . 2009-07-27 14:00 355584 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-07-27 14:00 . 2009-07-27 14:00 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\TuneUp Software
2009-07-27 13:59 . 2009-07-27 13:59 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-07-27 13:59 . 2009-07-27 13:59 -------- d-----w- c:\program files\TuneUp Utilities 2008
2009-07-27 13:59 . 2009-07-27 13:59 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-07-27 13:52 . 2009-07-27 13:52 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
2009-07-27 13:38 . 2009-07-27 13:38 198064 ----a-w- c:\documents and settings\XPPRESP3\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-07-27 13:38 . 2009-08-03 07:01 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\DMCache
2009-07-27 13:38 . 2009-07-27 13:39 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\IDM
2009-07-27 13:38 . 2009-07-27 13:39 -------- d-----w- c:\program files\Internet Download Manager
2009-07-27 13:34 . 2009-07-27 13:34 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\Media Player Classic
2009-07-27 13:33 . 2008-09-16 19:23 168448 ----a-w- c:\windows\system32\unrar.dll
2009-07-27 13:33 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-07-27 13:33 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-07-27 13:33 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-07-27 13:33 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\divx.dll
2009-07-27 13:33 . 2008-11-06 16:37 3596288 ----a-w- c:\windows\system32\qt-dx331.dll
2009-07-27 13:33 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-07-27 13:33 . 2009-06-02 16:11 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-07-27 13:33 . 2009-07-27 13:33 -------- d-----w- c:\program files\K-Lite Codec Pack
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-02 10:11 . 2009-07-27 06:36 -------- d-----w- c:\program files\IE7Pro
2009-08-02 10:04 . 2009-07-27 06:36 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\IE7Pro
2009-08-02 10:02 . 2009-07-27 17:51 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\PC Suite
2009-07-27 17:53 . 2009-07-27 17:51 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\Nokia
2009-07-27 17:51 . 2009-07-27 17:51 -------- d-----w- c:\program files\DIFX
2009-07-27 17:51 . 2009-07-27 17:51 -------- d-----w- c:\program files\Common Files\PCSuite
2009-07-27 17:51 . 2009-07-27 17:51 -------- d-----w- c:\program files\Common Files\Nokia
2009-07-27 17:51 . 2009-07-27 17:51 -------- d-----w- c:\program files\Nokia
2009-07-27 17:51 . 2009-07-27 17:51 -------- d-----w- c:\program files\PC Connectivity Solution
2009-07-27 16:45 . 2009-07-27 07:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-27 16:37 . 2009-07-27 07:23 -------- d-----w- c:\program files\HPQ
2009-07-27 16:23 . 2009-07-27 06:40 78328 ----a-w- c:\documents and settings\XPPRESP3\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-27 14:24 . 2007-08-08 17:39 218624 ----a-w- c:\windows\system32\uxtheme.dll
2009-07-27 08:17 . 2009-07-27 08:15 -------- d-----w- c:\program files\McAfee.com
2009-07-27 08:17 . 2009-07-27 08:15 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-07-27 08:11 . 2009-07-27 08:11 -------- d-----w- c:\program files\Citrix
2009-07-27 08:01 . 2009-07-27 08:01 -------- d-----w- c:\program files\CyberLink
2009-07-27 07:47 . 2009-07-27 07:10 -------- d-----w- c:\program files\Hewlett-Packard
2009-07-27 07:42 . 2009-07-27 07:42 -------- d-----w- c:\program files\Common Files\xing shared
2009-07-27 07:42 . 2009-07-27 07:42 -------- d-----w- c:\program files\Common Files\Real
2009-07-27 07:42 . 2009-07-27 07:42 -------- d-----w- c:\program files\Real
2009-07-27 07:31 . 2009-07-27 07:23 -------- d-----w- c:\program files\HP
2009-07-27 07:28 . 2009-07-27 07:26 1675 --sha-r- c:\windows\system32\drivers\103C_HP_NTBK_HP Pavilion dv2000 (RR092EA#ABV)_YN_0Pavi_Q2CE6450X4Q_EU_46_I30B3_SWistron_V61.65_BF.39_T070827_WXP2_L409_M2047_J120_7Intel_8Core2 T7200_92_#090727_N80864222_(RR092EA#ABV)_XMOBILE_CN10_Z_2F.39.MRK
2009-07-27 07:24 . 2009-07-27 07:24 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\HP
2009-07-27 07:24 . 2009-07-27 07:24 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-07-27 07:24 . 2009-07-27 07:24 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-07-27 07:14 . 2009-07-27 07:14 -------- d-----w- c:\program files\Broadcom
2009-07-27 07:14 . 2009-07-27 07:14 -------- d-----w- c:\program files\Synaptics
2009-07-27 07:14 . 2009-07-27 07:11 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-27 07:07 . 2009-07-27 07:07 -------- d-----w- c:\program files\NetWaiting
2009-07-27 07:07 . 2009-07-27 07:07 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\InstallShield
2009-07-27 07:07 . 2009-07-27 07:07 -------- d-----w- c:\program files\CONEXANT
2009-07-27 07:03 . 2009-07-27 07:03 -------- d-----w- c:\program files\WIDCOMM
2009-07-27 06:55 . 2009-07-27 06:54 3866624 ----a-w- c:\windows\system32\SET12.tmp
2009-07-27 06:46 . 2009-07-27 06:25 -------- d-----w- c:\program files\Graphics
2009-07-27 06:45 . 2009-07-27 06:26 -------- d-----w- c:\program files\Desktop
2009-07-27 06:45 . 2009-07-27 06:26 -------- d-----w- c:\program files\RocketDock
2009-07-27 06:40 . 2009-07-27 06:40 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\Gena01
2009-07-27 06:40 . 2009-07-27 06:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-07-27 06:39 . 2009-07-27 06:39 -------- d-----w- c:\program files\Yahoo!
2009-07-27 06:37 . 2009-07-27 06:37 -------- d-----w- c:\program files\MSN Messenger
2009-07-27 06:37 . 2009-07-27 06:37 -------- d-----w- c:\program files\Java
2009-07-27 06:37 . 2009-07-27 06:37 -------- d-----w- c:\program files\Common Files\Java
2009-07-27 06:37 . 2009-07-27 06:37 -------- d-----w- c:\program files\Common Files\Ahead
2009-07-27 06:37 . 2009-07-27 06:37 -------- d-----w- c:\program files\Nero
2009-07-27 06:37 . 2009-07-27 06:37 -------- d-----w- c:\program files\ieSpell
2009-07-27 06:31 . 2009-07-27 06:31 -------- d-----w- c:\program files\DAMN NFO Viewer
2009-07-27 06:30 . 2009-07-27 06:30 685816 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-07-27 06:30 . 2009-07-27 06:30 -------- d-----w- c:\program files\CPU-Z
2009-07-27 06:27 . 2009-07-27 06:27 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-07-27 06:25 . 2009-07-27 06:25 -------- d-----w- c:\program files\Windows Media Connect 2
.
------- Sigcheck -------
[7] 2007-08-08 16:25 823808 431DEFBB4A3D7B0DC062C1B064623A2F c:\windows\NiwradSoft Shell Pack\Backup\wininet.dll
[-] 2007-08-08 16:25 890368 6DF62B4F0EF432B874D4967E54072DFC c:\windows\system32\wininet.dll
[-] 2007-08-08 16:25 890368 6DF62B4F0EF432B874D4967E54072DFC c:\windows\VistaMizer\old\wininet.dll
[-] 2007-08-08 16:28 360704 A11391BE25035570AE4B8970920F2C74 c:\windows\system32\drivers\tcpip.sys
[-] 2004-08-04 14:00 541696 55ACA85EB80E2155E20211AAADDD711A c:\windows\system32\winlogon.exe
[7] 2004-08-04 14:00 502272 01C3346C241652F43AED8E2149881BFE c:\windows\VistaMizer\old\winlogon.exe
[-] 2005-09-28 23:35 2057344 C60248DDE015B0A73871A16576B7A945 c:\windows\$NtUninstallKB909095$\ntkrnlpa.exe
[7] 2005-10-11 23:54 2057344 DDBFA4EAE9251712F20193DD47B361BD c:\windows\Driver Cache\i386\ntkrnlpa.exe
[7] 2007-08-08 16:34 2017280 2DFB215E291E3D9B1CF9A6739B3BF16C c:\windows\NiwradSoft Shell Pack\Backup\ntkrnlpa.exe
[-] 2007-08-08 16:34 2180096 CD1A2EB31F570A1C84A4F8976A298F04 c:\windows\system32\ntkrnlpa.exe
[-] 2007-08-08 16:34 2180096 CD1A2EB31F570A1C84A4F8976A298F04 c:\windows\VistaMizer\old\ntkrnlpa.exe
[-] 2005-09-29 00:04 2180096 B919A39ACAFF2188FA699E22DCB5F13F c:\windows\$NtUninstallKB909095$\ntoskrnl.exe
[7] 2005-10-12 00:20 2180096 7B69EA89C7B9966BF552A070D97C5013 c:\windows\Driver Cache\i386\ntoskrnl.exe
[7] 2007-08-08 16:22 2137600 E6679C3023B17D8B78946BC5DF53FA20 c:\windows\NiwradSoft Shell Pack\Backup\ntoskrnl.exe
[-] 2007-08-08 16:22 2300416 288716AB5EE3766AF1A29AA61A793E58 c:\windows\system32\ntoskrnl.exe
[-] 2007-08-08 16:22 2300416 288716AB5EE3766AF1A29AA61A793E58 c:\windows\VistaMizer\old\ntoskrnl.exe
[-] 2007-08-08 16:40 1566208 20FE00E96A8B64F50037CB911F7292F7 c:\windows\explorer.exe
[-] 2007-08-08 16:40 950784 396ACC64ECEC61D7B2F8B53151B37028 c:\windows\NiwradSoft Shell Pack\Backup\explorer.exe
[-] 2007-08-08 16:40 1566208 20FE00E96A8B64F50037CB911F7292F7 c:\windows\VistaMizer\old\explorer.exe
[-] 2004-08-04 14:00 25088 5F1724D0E11EB88C95A3B73A6DD72779 c:\windows\system32\ctfmon.exe
[7] 2004-08-04 14:00 15360 24232996A38C0B0CF151C2140AE29FC8 c:\windows\VistaMizer\old\ctfmon.exe
[7] 2007-05-07 23:25 3584000 1D4E3B86C601A2497C99790CC4D7DF26 c:\windows\NiwradSoft Shell Pack\Backup\mshtml.dll
[-] 2007-05-07 23:25 3912192 D45BE50210B5A247E2AE9E7AF437C3A3 c:\windows\system32\mshtml.dll
[-] 2007-05-07 23:25 3912192 D45BE50210B5A247E2AE9E7AF437C3A3 c:\windows\system32\dllcache\mshtml.dll
[-] 2007-05-07 23:25 3912192 D45BE50210B5A247E2AE9E7AF437C3A3 c:\windows\VistaMizer\old\mshtml.dll
[-] 2007-08-08 16:39 1390080 751CB8B1BC6F428DC37C0C4D8A97F47A c:\windows\system32\comres.dll
[-] 2007-08-08 16:39 801792 F182079054D242025C2AEEF56396D37A c:\windows\VistaMizer\old\comres.dll
[-] 2007-08-08 16:21 724992 76F31C563F9ADA37E5031E00C36ACD0B c:\windows\system32\comctl32.dll
[7] 2007-08-08 16:21 617472 B0124CB21D28B1C9F678B566B6B57D92 c:\windows\VistaMizer\old\comctl32.dll
[7] 2004-08-04 14:00 921088 AEF3D788DBF40C7C4D204EA45EB0C505 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
[7] 2007-08-08 16:19 1054208 C4E80875C1CF1222FC5EFD0314AE5C01 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
[-] 2007-08-08 16:35 1580544 51C79052676267956DA3BEABADE3B328 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" [2007-08-08 124928]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-12 581693]
HP Pavilion Webcam Tray Icon.lnk - c:\program files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe [2009-7-27 102400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\IEPro\\MiniDM.exe"=
R3 NaiFiltr;NaiFiltr;c:\windows\system32\drivers\NaiFiltr.sys [7/27/2009 11:17 AM 23296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WudfServiceGroup REG_SZ hex(7):57,00,55,00,44,00,46,00,53,00,76,00,63,00,00,00,00,00
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-08-03 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 06:09]
2009-08-03 c:\windows\Tasks\McAfee.com Update Check (WW-XPPRESP3).job
- c:\progra~1\mcafee.com\agent\mcupdate.exe [2009-07-27 15:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.hp.com
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Lookup on Merriam Webster -
files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia -
files\ieSpell\wikipedia.HTM
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-08-03 10:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(948)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(1004)
c:\windows\system32\setupapi.dll
c:\windows\system32\psbase.dll
.
Completion time: 2009-08-03 10:05
ComboFix-quarantined-files.txt 2009-08-03 07:05
Pre-Run: 46,107,291,648 bytes free
Post-Run: 46,159,224,832 bytes free
269