تفضل التقرير ....
هذا التقرير من البرنامج الاول ..
ComboFix 09-09-25.01 - Administrator 09/26/2009 14:06.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.1470.997 [GMT 3:00]
Running from: g:\حل المشكله\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090918-0] *On-access scanning enabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\docume~1\ADMINI~1\LOCALS~1\Temp\cvasds0.dll
c:\docume~1\ADMINI~1\LOCALS~1\Temp\cvasds1.dll
c:\documents and settings\Administrator\سطح المكتب\AntivirusPro_2010.lnk
c:\documents and settings\Administrator\قائمة ابدأ\البرامج\بدء التشغيل\ikowin32.exe
c:\documents and settings\Administrator\قائمة ابدأ\البرامج\AntivirusPro_2010
c:\documents and settings\Administrator\قائمة ابدأ\البرامج\AntivirusPro_2010\AntivirusPro_2010.lnk
c:\documents and settings\Administrator\قائمة ابدأ\البرامج\AntivirusPro_2010\Uninstall.lnk
c:\documents and settings\Administrator\Application Data\boxegiw.ban
c:\documents and settings\Administrator\Application Data\ejaxehidew.vbs
c:\documents and settings\Administrator\Application Data\ekadiduva.sys
c:\documents and settings\Administrator\Application Data\irejazafu._sy
c:\documents and settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk
c:\documents and settings\Administrator\Application Data\wiaserva.log
c:\documents and settings\Administrator\Cookies\agilivuqav.dll
c:\documents and settings\Administrator\Cookies\bazopamigu.bin
c:\documents and settings\Administrator\Cookies\efezoq._dl
c:\documents and settings\Administrator\Cookies\esaxameg.inf
c:\documents and settings\Administrator\Cookies\fedafil.bat
c:\documents and settings\Administrator\Cookies\fejebonexu._dl
c:\documents and settings\Administrator\Cookies\gebiny.dll
c:\documents and settings\Administrator\Cookies\ikizej.db
c:\documents and settings\Administrator\Cookies\ipufovy.dl
c:\documents and settings\Administrator\Cookies\itizydofeh.ban
c:\documents and settings\Administrator\Cookies\navuquky.ban
c:\documents and settings\Administrator\Cookies\odakux.sys
c:\documents and settings\Administrator\Cookies\rite.com
c:\documents and settings\Administrator\Cookies\ticuvu.bin
c:\documents and settings\Administrator\Cookies\ujipidy.dl
c:\documents and settings\Administrator\Cookies\utuwimu._dl
c:\documents and settings\Administrator\Cookies\woqynobe.pif
c:\documents and settings\Administrator\Cookies\zekyv.exe
c:\documents and settings\Administrator\Local Settings\Application Data\igexizuxyc._sy
c:\documents and settings\Administrator\Local Settings\Application Data\lufof.dl
c:\documents and settings\Administrator\Local Settings\Application Data\nuxas.reg
c:\documents and settings\Administrator\Local Settings\Application Data\ocitipe.bin
c:\documents and settings\Administrator\Local Settings\Application Data\olag.bat
c:\documents and settings\Administrator\Local Settings\Application Data\ulipobi._dl
c:\documents and settings\Administrator\Local Settings\Application Data\unetimow.scr
c:\documents and settings\Administrator\Local Settings\Application Data\wefux.ban
c:\documents and settings\Administrator\Local Settings\Application Data\ymylif._sy
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\aqexad.dll
c:\documents and settings\Administrator\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\documents and settings\All Users\Application Data\ceviwarevu.reg
c:\documents and settings\All Users\Application Data\dubucyzas.ban
c:\documents and settings\All Users\Application Data\fawibymyd.com
c:\documents and settings\All Users\Application Data\fikuh._sy
c:\documents and settings\All Users\Application Data\liqope.reg
c:\documents and settings\All Users\Application Data\lotyner.ban
c:\documents and settings\All Users\Application Data\qesi.dll
c:\documents and settings\All Users\Application Data\ravefesug._sy
c:\documents and settings\All Users\Application Data\toqiti.lib
c:\documents and settings\All Users\Application Data\ucigoqyf.ban
c:\documents and settings\All Users\Application Data\unydu.lib
c:\documents and settings\All Users\Documents\awivuzovym.scr
c:\documents and settings\All Users\Documents\azequ.dl
c:\documents and settings\All Users\Documents\exeru.bat
c:\documents and settings\All Users\Documents\fyfa.exe
c:\documents and settings\All Users\Documents\lefydila.ban
c:\documents and settings\All Users\Documents\owytira.dl
c:\documents and settings\All Users\Documents\rebefu.reg
c:\documents and settings\All Users\Documents\sudutaqazu.sys
c:\documents and settings\All Users\Documents\taqebopa.vbs
c:\documents and settings\All Users\Documents\uxovecer.vbs
C:\lhh3v.exe
c:\program files\AntivirusPro_2010
c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg
c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe
c:\program files\AntivirusPro_2010\AVEngn.dll
c:\program files\AntivirusPro_2010\data\daily.cvd
c:\program files\AntivirusPro_2010\htmlayout.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcm80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcp80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcr80.dll
c:\program files\AntivirusPro_2010\pthreadVC2.dll
c:\program files\AntivirusPro_2010\Uninstall.exe
c:\program files\AntivirusPro_2010\wscui.cpl
c:\program files\Common Files\ezowys.inf
c:\program files\Common Files\hynevuzy.sys
c:\program files\Common Files\iqece.scr
c:\program files\Common Files\kahyto.reg
c:\program files\Common Files\ocybakulob.bat
c:\program files\Common Files\otefur.scr
C:\w9uxx92.exe
c:\windows\awape.pif
c:\windows\biwak.exe
c:\windows\japaro._dl
c:\windows\kiranig.scr
c:\windows\legaxit.reg
c:\windows\oqalyhux.pif
c:\windows\samudos.ban
c:\windows\system32\_scui.cpl
c:\windows\system32\fasotup.bat
c:\windows\system32\fywidoc.sys
c:\windows\system32\garugamifi.dl
c:\windows\system32\iqery.ban
c:\windows\system32\kakle.dll
c:\windows\system32\kiwiqud.sys
c:\windows\system32\nitalox.bin
c:\windows\system32\osimi.sys
c:\windows\system32\selure.pif
c:\windows\system32\umac.bin
c:\windows\system32\veqy.bin
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
c:\windows\system32\winitn.dll
c:\windows\system32\ykezaruf.bat
c:\windows\system32\ynuqihelaj.reg
c:\windows\ubalydotur.exe
c:\windows\uluzi.scr
c:\windows\uqyky._dl
c:\windows\utivus.ban
c:\windows\uxuba.bat
c:\windows\vocic.exe
c:\windows\xejy.dll
c:\windows\ycanaziwol.reg
c:\windows\zomyjujexu.inf
C:\wrsf.exe
D:\Autorun.inf
D:\lhh3v.exe
D:\w9uxx92.exe
D:\wrsf.exe
G:\autorun.inf
G:\w9uxx92.exe
G:\wrsf.exe
.
((((((((((((((((((((((((( Files Created from 2009-08-26 to 2009-09-26 )))))))))))))))))))))))))))))))
.
2009-09-26 10:14 . 2009-09-26 10:14 11944 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\ymilyxahe.dat
2009-09-26 06:03 . 2009-09-26 06:03 -------- d-----w- c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-09-26 05:43 . 2009-09-26 05:43 17071 ----a-w- c:\windows\nuletozoba.dat
2009-09-26 05:43 . 2009-09-26 05:43 14286 ----a-w- c:\program files\Common Files\ifixi.dat
2009-09-26 05:43 . 2009-09-26 05:43 11595 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\kyxuk.dat
2009-09-26 05:14 . 2009-09-26 05:14 19499 ----a-w- c:\windows\opedisu.com
2009-09-26 05:14 . 2009-09-26 05:14 11163 ----a-w- c:\windows\system32\qotebac.dat
2009-09-26 05:01 . 2009-08-17 16:04 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-09-26 05:01 . 2009-08-17 16:04 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-09-26 05:01 . 2009-08-17 16:03 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-09-26 05:01 . 2009-08-17 16:02 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-09-26 05:01 . 2009-08-17 16:06 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-09-26 05:01 . 2009-08-17 16:06 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-09-26 05:01 . 2009-08-17 16:05 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-09-26 05:01 . 2009-08-17 16:05 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-09-26 05:01 . 2009-08-17 16:10 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-09-26 04:51 . 2009-09-26 04:51 15308 ----a-w- c:\program files\Common Files\kugikuk.dat
2009-09-26 04:43 . 2009-09-26 00:53 116397 --sh--r- C:\mranjm.exe
2009-09-26 04:07 . 2009-09-26 04:07 10281 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\epusodecot.dat
2009-09-26 02:00 . 2009-09-26 02:00 43520 ----a-w- c:\windows\system32\restorer32_a.exe
2009-09-26 02:00 . 2009-09-26 02:00 43520 ----a-w- c:\documents and settings\Administrator\restorer32_a.exe
2009-09-25 06:59 . 2009-09-25 06:59 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-09-25 06:58 . 2009-09-25 06:58 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-25 06:57 . 2009-09-25 06:57 -------- d-----w- c:\program files\Microsoft
2009-09-25 06:45 . 2009-09-25 06:45 -------- d--h--w- c:\windows\PIF
2009-09-25 05:45 . 2009-09-25 08:47 -------- d-----w- c:\windows\SxsCaPendDel
2009-09-15 09:17 . 2009-09-15 09:17 -------- d-----w- c:\documents and settings\Administrator\Application Data\FlashFXP
2009-09-15 01:58 . 2003-09-18 14:01 10112 ----a-w- c:\windows\system32\drivers\pmfilt.sys
2009-09-15 01:58 . 2003-09-18 14:01 48672 ----a-w- c:\windows\system32\drivers\pmhelp.sys
2009-09-15 01:58 . 2009-09-15 01:58 -------- d-----w- c:\program files\GLDirect
2009-09-15 01:58 . 2009-09-15 01:58 -------- d-----w- c:\windows\gldirect
2009-09-15 01:38 . 2009-09-15 01:38 -------- d-----w- c:\program files\Alwil Software
2009-09-14 23:40 . 2009-09-14 23:40 -------- d-----w- c:\documents and settings\Administrator\Application Data\TeamViewer
2009-09-14 23:40 . 2009-09-14 23:40 -------- d-----w- c:\program files\TeamViewer
2009-09-14 23:40 . 2009-09-14 23:40 -------- d-----w- c:\documents and settings\Administrator\temp
2009-09-14 22:01 . 2004-08-03 20:55 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-09-14 21:58 . 2009-09-14 21:58 -------- d-----w- c:\program files\Common Files\Vbox
2009-09-14 21:56 . 2009-09-14 21:56 -------- d-----w- c:\windows\Downloaded Installations
2009-09-14 21:41 . 2009-09-14 21:41 -------- d-----w- c:\program files\Windows Live Safety Center
2009-09-14 21:40 . 2009-09-14 21:40 -------- d-----w- c:\documents and settings\Administrator\Application Data\Thinstall
2009-09-14 20:57 . 2009-09-14 21:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\VersionTracker Pro
2009-09-14 20:57 . 2009-09-14 20:57 -------- d-----w- c:\program files\TechTracker
2009-09-14 20:51 . 2009-09-14 20:51 -------- d-----w- c:\windows\B440D659FECA4BDDA12B5C9F05790FF3.TMP
2009-09-14 20:48 . 2009-09-14 20:48 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith
2009-09-14 20:48 . 2009-09-14 20:48 -------- d-----w- c:\program files\TechSmith
2009-09-14 20:48 . 2009-09-14 20:48 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\TechSmith
2009-09-14 20:47 . 2009-09-14 20:47 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-14 06:15 . 2009-09-15 03:32 -------- d-----w- c:\program files\AskBarDis
2009-09-14 06:15 . 2009-09-15 09:21 -------- d-----w- c:\program files\FlashFXP
2009-09-14 06:15 . 2009-09-14 06:15 -------- d-----w- c:\documents and settings\All Users\Application Data\FlashFXP
2009-09-13 20:33 . 2009-09-13 20:33 -------- d-----w- c:\windows\system32\LogFiles
2009-09-13 11:39 . 2009-09-13 11:39 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Identities
2009-09-13 09:49 . 2009-09-13 09:49 -------- d-----w- c:\windows\Sun
2009-09-13 05:59 . 2009-09-13 05:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Adobe Systems
2009-09-13 05:59 . 2009-09-13 05:59 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2009-09-13 05:52 . 1999-12-17 05:13 86016 ----a-w- c:\windows\unvise32.exe
2009-09-13 05:51 . 2009-09-13 05:52 -------- d-----w- c:\program files\SWiSHmax
2009-09-13 05:46 . 2009-09-13 05:46 -------- d-----w- c:\program files\Common Files\xing shared
2009-09-13 05:45 . 2009-09-13 09:43 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2009-09-13 05:45 . 2009-09-13 05:48 -------- d-----w- c:\program files\Google
2009-09-13 05:45 . 2009-09-13 05:45 -------- d-----w- c:\program files\Common Files\Real
2009-09-13 05:45 . 2009-09-13 05:45 -------- d-----w- c:\program files\Real
2009-09-13 04:00 . 2009-09-13 04:00 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache
2009-09-13 04:00 . 2009-09-13 04:00 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-09-13 03:59 . 2009-09-13 03:59 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-09-13 03:59 . 2009-09-13 03:59 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-09-13 03:54 . 2006-10-17 09:06 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-09-13 03:54 . 2006-10-17 09:06 78336 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2009-09-13 03:25 . 2004-08-03 21:45 14720 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-09-13 03:25 . 2004-08-03 21:45 14720 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2009-09-13 03:15 . 2009-09-26 11:00 -------- d-----w- c:\documents and settings\Administrator\Tracing
2009-09-13 03:10 . 2006-11-29 10:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-09-13 03:08 . 2009-09-13 03:08 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-13 01:15 . 2009-09-13 01:15 -------- d-----w- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-26 11:10 . 2009-09-12 21:50 -------- d-----w- c:\documents and settings\Administrator\Application Data\DMCache
2009-09-26 11:04 . 2001-09-19 10:00 58722 ----a-w- c:\windows\system32\perfc001.dat
2009-09-26 11:04 . 2001-09-19 10:00 328418 ----a-w- c:\windows\system32\perfh001.dat
2009-09-26 05:43 . 2009-09-26 05:43 14037 ----a-w- c:\documents and settings\All Users\Application Data\ujozilu.dat
2009-09-26 05:14 . 2009-09-26 05:14 18563 ----a-w- c:\program files\Common Files\bixyw._sy
2009-09-26 04:51 . 2009-09-26 04:51 18237 ----a-w- c:\program files\Common Files\avetemo.lib
2009-09-26 04:51 . 2009-09-26 04:51 13116 ----a-w- c:\documents and settings\All Users\Application Data\alewyt.dat
2009-09-26 04:07 . 2009-09-26 04:07 11823 ----a-w- c:\program files\Common Files\sowi.db
2009-09-26 02:00 . 2009-09-26 02:00 158832 ----a-w- c:\documents and settings\Administrator\Application Data\lizkavd.exe
2009-09-26 02:00 . 2009-09-26 02:00 14848 ----a-w- c:\documents and settings\Administrator\Application Data\svcst.exe
2009-09-26 02:00 . 2009-09-26 02:00 14848 ----a-w- c:\documents and settings\Administrator\Application Data\seres.exe
2009-09-25 14:15 . 2009-09-12 21:50 -------- d-----w- c:\documents and settings\Administrator\Application Data\IDM
2009-09-25 08:08 . 2009-09-12 20:49 266376 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-25 06:59 . 2009-09-12 22:25 -------- d-----w- c:\program files\Windows Live
2009-09-13 06:46 . 2009-09-12 22:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-09-13 06:00 . 2009-09-12 21:53 -------- d-----w- c:\program files\Common Files\Adobe
2009-09-13 05:45 . 2009-09-12 22:04 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-09-13 05:45 . 2009-09-12 21:58 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-09-13 05:28 . 2009-09-12 21:50 -------- d-----w- c:\program files\Internet Download Manager
2009-09-13 05:03 . 2009-09-12 22:25 -------- d-----w- c:\program files\Messenger Plus! Live
2009-09-13 02:01 . 2009-09-12 21:58 -------- d-----w- c:\program files\RocketDock
2009-09-12 23:50 . 2009-09-12 22:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Software rule flag owns
2009-09-12 23:30 . 2009-09-12 23:30 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-09-12 23:30 . 2009-09-12 23:30 -------- d-----w- c:\program files\REALTEK RTL8187 Wireless LAN Driver and Utility
2009-09-12 23:30 . 2009-09-12 21:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-12 23:30 . 2009-09-12 21:30 -------- d-----w- c:\program files\Common Files\InstallShield
2009-09-12 23:20 . 2009-09-12 21:57 -------- d-----w- c:\program files\The KMPlayer
2009-09-12 23:20 . 2009-09-12 22:04 2846720 ----a-w- c:\windows\system32\agsaamj.dll
2009-09-12 23:20 . 2009-09-12 22:04 626688 ----a-w- c:\windows\system32\agsaamh.dll
2009-09-12 23:20 . 2009-09-12 22:04 90112 ----a-w- c:\windows\system32\agsaami.dll
2009-09-12 23:20 . 2009-09-12 22:04 753664 ----a-w- c:\windows\system32\agsaamg.dll
2009-09-12 23:20 . 2009-09-12 22:04 551424 ----a-w- c:\windows\system32\agsaame.dll
2009-09-12 23:20 . 2009-09-12 22:04 544256 ----a-w- c:\windows\system32\agsaamd.dll
2009-09-12 23:20 . 2009-09-12 22:04 372736 ----a-w- c:\windows\system32\agsaamc.dll
2009-09-12 23:20 . 2009-09-12 22:04 538624 ----a-w- c:\windows\system32\agsaamb.dll
2009-09-12 23:20 . 2009-09-12 22:04 331776 ----a-w- c:\windows\system32\agsaama.dll
2009-09-12 22:32 . 2009-09-12 22:06 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-09-12 22:28 . 2009-09-12 22:17 -------- d-----w- c:\program files\Hotspot_Shield
2009-09-12 22:27 . 2009-09-12 22:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\Chic bike barb
2009-09-12 22:26 . 2009-09-12 22:26 -------- d-----w- c:\program files\Chic bike barb
2009-09-12 22:25 . 2009-09-12 22:25 -------- d-----w- c:\program files\Circle Developement
2009-09-12 22:17 . 2009-09-12 22:17 0 ----a-w- c:\windows\nsreg.dat
2009-09-12 22:17 . 2009-09-12 22:17 -------- d-----w- c:\program files\Conduit
2009-09-12 22:12 . 2009-09-12 21:59 -------- d-----w- c:\program files\Java
2009-09-12 22:11 . 2009-09-12 22:11 -------- d-----w- c:\program files\Common Files\Java
2009-09-12 22:03 . 2009-09-12 22:03 -------- d-----w- c:\program files\Microsoft.NET
2009-09-12 22:03 . 2009-09-12 22:03 -------- d-----w- c:\program files\Ozone
2009-09-12 22:02 . 2009-09-12 22:02 -------- d-----w- c:\program files\Ashampoo
2009-09-12 21:59 . 2009-09-12 21:59 410976 ----a-w- c:\windows\system32\deploytk.dll
2009-09-12 21:58 . 2009-09-12 21:58 -------- d-----w- c:\program files\VideoLAN
2009-09-12 21:58 . 2009-09-12 21:58 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-09-12 21:57 . 2009-09-12 21:57 -------- d-----w- c:\program files\CCleaner
2009-09-12 21:54 . 2009-09-12 21:54 -------- d-----w- c:\program files\Golden Al-Wafi Translator
2009-09-12 21:53 . 2009-09-12 21:53 172032 ------w- c:\windows\Setup1.exe
2009-09-12 21:53 . 2009-09-12 21:53 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-09-12 21:34 . 2009-09-12 21:33 -------- d-----w- c:\program files\VIA
2009-09-12 21:31 . 2009-09-12 21:31 -------- d-----w- c:\program files\S3
2009-09-12 21:31 . 2009-09-12 21:31 -------- d-----w- c:\program files\Realtek AC97
2009-09-12 20:40 . 2009-09-12 20:40 -------- d-----w- c:\program files\microsoft frontpage
2009-09-12 20:37 . 2009-09-12 20:37 22144 ----a-w- c:\windows\system32\emptyregdb.dat
2009-07-26 13:44 . 2009-07-26 13:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-10 10:07 . 2009-07-10 10:07 306544 ----a-w- c:\windows\WLXPGSS.SCR
.
------- Sigcheck -------
[-] 2008-05-21 . D74083DCEC51D5291EF24D8D055D133A . 1547776 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"= "c:\program files\Hotspot_Shield\tbHots.dll" [2008-03-13 1524248]
[HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-08-13 14:47 308616 ----a-w- c:\program files\AskBarDis\bar\bin\askBar1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
2008-03-13 07:30 1524248 ----a-w- c:\program files\Hotspot_Shield\tbHots.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"= "c:\program files\Hotspot_Shield\tbHots.dll" [2008-03-13 1524248]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar1.dll" [2008-08-13 308616]
[HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}"= "c:\program files\Hotspot_Shield\tbHots.dll" [2008-03-13 1524248]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar1.dll" [2008-08-13 308616]
[HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2007-12-21 2573744]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-13 39408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-03 1667584]
"restorer32_a"="c:\documents and settings\Administrator\restorer32_a.exe" [2009-09-26 43520]
"mserv"="c:\documents and settings\Administrator\Application Data\seres.exe" [2009-09-26 14848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RaidTool"="c:\program files\VIA\RAID\raid_tool.exe" [2004-10-11 589824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-12 136600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-13 185896]
"GLDStart"="c:\program files\GLDirect\gldirect.exe" [2003-09-18 118784]
"restorer32_a"="c:\windows\system32\restorer32_a.exe" [2009-09-26 43520]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2005-11-11 90112]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2005-03-07 53248]
"VTTrayp"="VTtrayp.exe" - c:\windows\system32\VTTrayp.exe [2005-10-31 163840]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\Administrator\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
REALTEK RTL8187 Wireless LAN Utility.lnk - c:\program files\REALTEK RTL8187 Wireless LAN Driver and Utility\RtWLan.exe [2009-9-13 737280]
Snagit 9.lnk - c:\program files\TechSmith\Snagit 9\Snagit32.exe [2009-4-17 7226184]
§ک ں颬نïé ںé«©ïم é• Microsoft Office OneNote 2003.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2003-8-6 51776]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 pmfilt;pmfilt;c:\windows\system32\drivers\pmfilt.sys [15/09/2009 04:58 ص 10112]
R0 pmhelp;pmhelp;c:\windows\system32\drivers\pmhelp.sys [15/09/2009 04:58 ص 48672]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [26/09/2009 08:01 ص 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [26/09/2009 08:01 ص 20560]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [13/09/2009 02:30 ص 194304]
R3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [13/09/2009 02:30 ص 13532]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - SJYPKT
.
Contents of the 'Scheduled Tasks' folder
2009-09-26 c:\windows\Tasks\AD829BFF91850F53.job
- c:\docume~1\admini~1\applic~1\chicbi~1\Thunk joy bin.exe [2009-09-12 22:27]
2009-09-26 c:\windows\Tasks\User_Feed_Synchronization-{2BBEC606-544B-4FE5-90B7-B38083BC2B7D}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:58]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d6ypn0pf.default\
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-softwaredart - c:\docume~1\ADMINI~1\APPLIC~1\CHICBI~1\partinsideowns.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-09-26 14:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1417001333-2049760794-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,23,2c,5d,34,11,23,3c,44,b6,4c,c9,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,23,2c,5d,34,11,23,3c,44,b6,4c,c9,\
.
Completion time: 2009-09-26 14:11
ComboFix-quarantined-files.txt 2009-09-26 11:11
Pre-Run: 24,637,718,528 bytes free
Post-Run: 25,019,310,080 bytes free
395