ComboFix 08-10-21.03 - adel 2008-10-22 14:26:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.696 [GMT 3:00]
Running from: C:\Documents and Settings\adel\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\adel\Application Data\tazebama
C:\zPharaoh.exe
D:\Autorun.inf
D:\zPharaoh.exe
G:\Autorun.inf
G:\zPharaoh.exe
.
((((((((((((((((((((((((( Files Created from 2008-09-22 to 2008-10-22 )))))))))))))))))))))))))))))))
.
2008-10-22 03:00 . 2008-10-22 03:00 <DIR> d-------- C:\WINDOWS\LastGood
2008-10-21 18:29 . 2008-10-21 18:29 <DIR> d-------- C:\Documents and Settings\Administrator
2008-10-18 23:03 . 2008-10-18 23:03 <DIR> d-------- C:\Program Files\Common Files\HP
2008-10-18 22:12 . 2004-01-05 10:30 38,867 --------- C:\WINDOWS\hpomdl03.dat.temp
2008-10-18 22:12 . 2008-10-18 22:40 29,090 --------- C:\WINDOWS\hpoins03.dat.temp
2008-10-18 01:16 . 2008-10-22 01:01 32,768 --a------ C:\Documents and Settings\tazebama.dll
2008-10-18 00:49 . 2008-10-21 00:38 126 --a------ C:\1.taz
2008-10-17 21:21 . 2008-10-17 21:21 <DIR> d-------- C:\Program Files\GetData
2008-10-17 21:20 . 2008-10-17 21:24 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-17 18:47 . 2008-10-17 18:47 <DIR> d-------- C:\Documents and Settings\tazebama.dl_
2008-10-17 18:47 . 2008-10-17 18:47 <DIR> d-------- C:\Documents and Settings\hook.dl_
2008-10-17 00:43 . 2008-10-17 00:43 <DIR> d-------- C:\Program Files\SplitCam
2008-10-16 02:06 . 2004-01-05 10:30 51,056 -ra------ C:\WINDOWS\system32\drivers\hpzid412.sys
2008-10-16 02:06 . 2004-01-05 10:30 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-10-16 02:05 . 2004-01-05 10:30 21,488 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-10-16 02:05 . 2008-04-14 00:15 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-10-16 02:05 . 2008-04-14 00:15 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-10-16 01:56 . 2008-10-16 01:56 <DIR> d-------- C:\Program Files\AskSearch
2008-10-16 01:56 . 2008-10-16 01:56 <DIR> d-------- C:\Program Files\AskBarDis
2008-10-16 01:50 . 2008-10-16 01:50 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-10-16 01:50 . 2003-12-11 11:15 626,960 -ra------ C:\WINDOWS\system32\hpvaut32.dll
2008-10-16 01:50 . 2003-12-11 11:15 487,424 -ra------ C:\WINDOWS\system32\hpvcp70.dll
2008-10-16 01:50 . 2003-12-11 11:15 344,064 -ra------ C:\WINDOWS\system32\hpvcr70.dll
2008-10-16 01:50 . 2003-12-11 11:15 44,544 -ra------ C:\WINDOWS\system32\MSXML4a.dll
2008-10-16 01:46 . 2008-10-16 01:46 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-10-16 01:44 . 2008-10-18 23:04 <DIR> d-------- C:\Program Files\HP
2008-10-16 01:43 . 2004-01-05 10:30 38,867 --------- C:\WINDOWS\hpomdl03.dat
2008-10-16 01:43 . 2008-10-18 23:07 29,134 --a------ C:\WINDOWS\hpoins03.dat
2008-10-16 01:37 . 2008-04-14 00:17 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-10-16 01:37 . 2008-04-14 00:17 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-10-16 01:36 . 2008-04-14 00:15 32,128 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-10-16 01:36 . 2008-04-14 00:15 32,128 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-10-15 20:39 . 2008-10-15 20:39 <DIR> d-------- C:\Program Files\Hotspot Shield
2008-10-15 14:15 . 2008-10-15 14:15 <DIR> d-------- C:\Documents and Settings\adel\Application Data\Convivea
2008-10-14 18:45 . 2008-10-14 18:45 <DIR> d-------- C:\Documents and Settings\adel\Application Data\Media Player Classic
2008-10-14 18:06 . 2008-10-22 14:23 <DIR> d-------- C:\Documents and Settings\adel\Application Data\uTorrent
2008-10-14 18:01 . 2008-10-14 18:01 <DIR> d-------- C:\Documents and Settings\adel\Application Data\CyberLink
2008-10-14 17:44 . 2008-10-16 01:52 <DIR> d-------- C:\Documents and Settings\adel\Application Data\Paltalk
2008-10-14 17:21 . 2008-10-14 17:21 <DIR> d-------- C:\Documents and Settings\adel\Application Data\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-18 19:12 --------- d-----w C:\Program Files\Paltalk Messenger
2008-10-17 16:09 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-10-17 16:09 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-10-16 21:43 13,824 ----a-w C:\WINDOWS\system32\drivers\splitcam.sys
2008-10-15 11:15 --------- d-----w C:\Program Files\Bit Che
2008-10-14 16:38 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-10-14 16:38 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-10-14 16:38 --------- d-----w C:\Program Files\Common Files\xing shared
2008-10-14 16:38 --------- d-----w C:\Program Files\Common Files\Real
2008-10-14 15:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-14 15:07 --------- d-----w C:\Program Files\FairStars Audio Converter
2008-10-14 15:06 --------- d-----w C:\Program Files\uTorrent
2008-10-14 15:04 155,995 ----a-w C:\WINDOWS\java\Packages\XZH7Z335.ZIP
2008-10-14 15:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-10-14 14:59 --------- d-----w C:\Program Files\CyberLink
2008-10-14 14:59 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-14 14:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\MumboJumbo
2008-10-14 14:55 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-14 14:52 --------- d-----w C:\Program Files\Luxor 2
2008-10-14 14:52 --------- d-----w C:\Program Files\BFG
2008-10-14 14:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trymedia
2008-10-14 14:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-10-14 14:49 --------- d-----w C:\Program Files\Real
2008-10-14 14:48 --------- d-----w C:\Program Files\MSN Messenger
2008-10-14 14:44 172,032 ------w C:\WINDOWS\Setup1.exe
2008-10-14 14:44 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-10-14 14:43 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-10-14 14:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-14 14:35 --------- d-----w C:\Program Files\MSBuild
2008-10-14 14:35 --------- d-----w C:\Program Files\Microsoft Works
2008-10-14 14:21 --------- d-----w C:\Program Files\Realtek
2008-10-14 14:19 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-10-14 14:15 --------- d-----w C:\Program Files\Yahoo!
2008-10-14 14:15 --------- d-----w C:\Program Files\Intel
2008-10-14 13:54 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 17:20 279944 --a------ C:\Program Files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "C:\Program Files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "C:\Program Files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2008-10-17 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-28 118784]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2008-10-17 49152]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-10-14 185872]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 49152]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 C:\WINDOWS\system32\bthprops.cpl]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-06-15 C:\WINDOWS\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\adel\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [26/10/2006 08:24:54 ê 98632]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [16/09/2003 05:19:24 ­ 237568]
PalTalk.lnk - C:\Program Files\Paltalk Messenger\paltalk.exe [11/09/2008 12:40:43 ­ 11713536]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [14/10/2008 05:50:44 ê 389120]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2007-06-08 27136]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3dc95c49-9bcf-11dd-beb4-001167558f69}]
\Shell\AutoRun\command - F:\zPharaoh.exe
\Shell\explore\command - F:\zPharaoh.exe
\Shell\open\command - F:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6b78c945-99f8-11dd-bea4-001167558f69}]
\Shell\AutoRun\command - F:\zPharaoh.exe
\Shell\explore\command - F:\zPharaoh.exe
\Shell\open\command - F:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a173242e-9b29-11dd-beb1-001167558f69}]
\Shell\AutoRun\command - F:\zPharaoh.exe
\Shell\explore\command - F:\zPharaoh.exe
\Shell\open\command - F:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a173242f-9b29-11dd-beb1-001167558f69}]
\Shell\AutoRun\command - H:\zPharaoh.exe
\Shell\explore\command - H:\zPharaoh.exe
\Shell\open\command - H:\zPharaoh.exe
*Newly Created Service* - BITS
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-zyz1 - c:\zyz_auto_killer\run2.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.222z.net/
R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.yahoo.com/
R1 -: HKCU-SearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct=&gc=1&q=%s
O8 -: ت&صدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 -: Microsoft XML Parser for Java -
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-22 14:31:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-22 14:32:25
ComboFix-quarantined-files.txt 2008-10-22 11:31:55
Pre-Run: 4,614,574,080 bytes free
Post-Run: 5,476,012,032 bytes free
196 --- E O F --- 2008-10-22 00:00:30
ComboFix 08-10-21.03 - adel 2008-10-22 14:26:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.696 [GMT 3:00]
Running from: C:\Documents and Settings\adel\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\adel\Application Data\tazebama
C:\zPharaoh.exe
D:\Autorun.inf
D:\zPharaoh.exe
G:\Autorun.inf
G:\zPharaoh.exe
.
((((((((((((((((((((((((( Files Created from 2008-09-22 to 2008-10-22 )))))))))))))))))))))))))))))))
.
2008-10-22 03:00 . 2008-10-22 03:00 <DIR> d-------- C:\WINDOWS\LastGood
2008-10-21 18:29 . 2008-10-21 18:29 <DIR> d-------- C:\Documents and Settings\Administrator
2008-10-18 23:03 . 2008-10-18 23:03 <DIR> d-------- C:\Program Files\Common Files\HP
2008-10-18 22:12 . 2004-01-05 10:30 38,867 --------- C:\WINDOWS\hpomdl03.dat.temp
2008-10-18 22:12 . 2008-10-18 22:40 29,090 --------- C:\WINDOWS\hpoins03.dat.temp
2008-10-18 01:16 . 2008-10-22 01:01 32,768 --a------ C:\Documents and Settings\tazebama.dll
2008-10-18 00:49 . 2008-10-21 00:38 126 --a------ C:\1.taz
2008-10-17 21:21 . 2008-10-17 21:21 <DIR> d-------- C:\Program Files\GetData
2008-10-17 21:20 . 2008-10-17 21:24 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-17 18:47 . 2008-10-17 18:47 <DIR> d-------- C:\Documents and Settings\tazebama.dl_
2008-10-17 18:47 . 2008-10-17 18:47 <DIR> d-------- C:\Documents and Settings\hook.dl_
2008-10-17 00:43 . 2008-10-17 00:43 <DIR> d-------- C:\Program Files\SplitCam
2008-10-16 02:06 . 2004-01-05 10:30 51,056 -ra------ C:\WINDOWS\system32\drivers\hpzid412.sys
2008-10-16 02:06 . 2004-01-05 10:30 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-10-16 02:05 . 2004-01-05 10:30 21,488 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-10-16 02:05 . 2008-04-14 00:15 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-10-16 02:05 . 2008-04-14 00:15 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-10-16 01:56 . 2008-10-16 01:56 <DIR> d-------- C:\Program Files\AskSearch
2008-10-16 01:56 . 2008-10-16 01:56 <DIR> d-------- C:\Program Files\AskBarDis
2008-10-16 01:50 . 2008-10-16 01:50 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-10-16 01:50 . 2003-12-11 11:15 626,960 -ra------ C:\WINDOWS\system32\hpvaut32.dll
2008-10-16 01:50 . 2003-12-11 11:15 487,424 -ra------ C:\WINDOWS\system32\hpvcp70.dll
2008-10-16 01:50 . 2003-12-11 11:15 344,064 -ra------ C:\WINDOWS\system32\hpvcr70.dll
2008-10-16 01:50 . 2003-12-11 11:15 44,544 -ra------ C:\WINDOWS\system32\MSXML4a.dll
2008-10-16 01:46 . 2008-10-16 01:46 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-10-16 01:44 . 2008-10-18 23:04 <DIR> d-------- C:\Program Files\HP
2008-10-16 01:43 . 2004-01-05 10:30 38,867 --------- C:\WINDOWS\hpomdl03.dat
2008-10-16 01:43 . 2008-10-18 23:07 29,134 --a------ C:\WINDOWS\hpoins03.dat
2008-10-16 01:37 . 2008-04-14 00:17 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-10-16 01:37 . 2008-04-14 00:17 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-10-16 01:36 . 2008-04-14 00:15 32,128 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-10-16 01:36 . 2008-04-14 00:15 32,128 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-10-15 20:39 . 2008-10-15 20:39 <DIR> d-------- C:\Program Files\Hotspot Shield
2008-10-15 14:15 . 2008-10-15 14:15 <DIR> d-------- C:\Documents and Settings\adel\Application Data\Convivea
2008-10-14 18:45 . 2008-10-14 18:45 <DIR> d-------- C:\Documents and Settings\adel\Application Data\Media Player Classic
2008-10-14 18:06 . 2008-10-22 14:23 <DIR> d-------- C:\Documents and Settings\adel\Application Data\uTorrent
2008-10-14 18:01 . 2008-10-14 18:01 <DIR> d-------- C:\Documents and Settings\adel\Application Data\CyberLink
2008-10-14 17:44 . 2008-10-16 01:52 <DIR> d-------- C:\Documents and Settings\adel\Application Data\Paltalk
2008-10-14 17:21 . 2008-10-14 17:21 <DIR> d-------- C:\Documents and Settings\adel\Application Data\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-18 19:12 --------- d-----w C:\Program Files\Paltalk Messenger
2008-10-17 16:09 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-10-17 16:09 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-10-16 21:43 13,824 ----a-w C:\WINDOWS\system32\drivers\splitcam.sys
2008-10-15 11:15 --------- d-----w C:\Program Files\Bit Che
2008-10-14 16:38 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-10-14 16:38 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-10-14 16:38 --------- d-----w C:\Program Files\Common Files\xing shared
2008-10-14 16:38 --------- d-----w C:\Program Files\Common Files\Real
2008-10-14 15:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-14 15:07 --------- d-----w C:\Program Files\FairStars Audio Converter
2008-10-14 15:06 --------- d-----w C:\Program Files\uTorrent
2008-10-14 15:04 155,995 ----a-w C:\WINDOWS\java\Packages\XZH7Z335.ZIP
2008-10-14 15:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-10-14 14:59 --------- d-----w C:\Program Files\CyberLink
2008-10-14 14:59 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-14 14:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\MumboJumbo
2008-10-14 14:55 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-14 14:52 --------- d-----w C:\Program Files\Luxor 2
2008-10-14 14:52 --------- d-----w C:\Program Files\BFG
2008-10-14 14:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trymedia
2008-10-14 14:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-10-14 14:49 --------- d-----w C:\Program Files\Real
2008-10-14 14:48 --------- d-----w C:\Program Files\MSN Messenger
2008-10-14 14:44 172,032 ------w C:\WINDOWS\Setup1.exe
2008-10-14 14:44 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-10-14 14:43 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-10-14 14:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-14 14:35 --------- d-----w C:\Program Files\MSBuild
2008-10-14 14:35 --------- d-----w C:\Program Files\Microsoft Works
2008-10-14 14:21 --------- d-----w C:\Program Files\Realtek
2008-10-14 14:19 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-10-14 14:15 --------- d-----w C:\Program Files\Yahoo!
2008-10-14 14:15 --------- d-----w C:\Program Files\Intel
2008-10-14 13:54 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 17:20 279944 --a------ C:\Program Files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "C:\Program Files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "C:\Program Files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2008-10-17 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-28 118784]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2008-10-17 49152]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-10-14 185872]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 49152]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 C:\WINDOWS\system32\bthprops.cpl]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-06-15 C:\WINDOWS\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\adel\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [26/10/2006 08:24:54 ê 98632]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [16/09/2003 05:19:24 ­ 237568]
PalTalk.lnk - C:\Program Files\Paltalk Messenger\paltalk.exe [11/09/2008 12:40:43 ­ 11713536]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [14/10/2008 05:50:44 ê 389120]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2007-06-08 27136]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3dc95c49-9bcf-11dd-beb4-001167558f69}]
\Shell\AutoRun\command - F:\zPharaoh.exe
\Shell\explore\command - F:\zPharaoh.exe
\Shell\open\command - F:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6b78c945-99f8-11dd-bea4-001167558f69}]
\Shell\AutoRun\command - F:\zPharaoh.exe
\Shell\explore\command - F:\zPharaoh.exe
\Shell\open\command - F:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a173242e-9b29-11dd-beb1-001167558f69}]
\Shell\AutoRun\command - F:\zPharaoh.exe
\Shell\explore\command - F:\zPharaoh.exe
\Shell\open\command - F:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a173242f-9b29-11dd-beb1-001167558f69}]
\Shell\AutoRun\command - H:\zPharaoh.exe
\Shell\explore\command - H:\zPharaoh.exe
\Shell\open\command - H:\zPharaoh.exe
*Newly Created Service* - BITS
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-zyz1 - c:\zyz_auto_killer\run2.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.222z.net/
R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.yahoo.com/
R1 -: HKCU-SearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct=&gc=1&q=%s
O8 -: ت&صدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 -: Microsoft XML Parser for Java -
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-22 14:31:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-22 14:32:25
ComboFix-quarantined-files.txt 2008-10-22 11:31:55
Pre-Run: 4,614,574,080 bytes free
Post-Run: 5,476,012,032 bytes free
196 --- E O F --- 2008-10-22 00:00:30
وشاكر لك ابو ريما وكذلك ma222
وهذا التقرير حسب تو جيهاتكم نفع الله بكم