ComboFix
ComboFix 08-09-01.03 - Mwasel 09/03/2008 10:50:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.578 [GMT 3:00]
Running from: C:\Documents and Settings\mwasel\Desktop\ComboFix\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\winst.log
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-08-03 to 2008-09-03 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-02 08:42 --------- d-----w C:\Program Files\YouTube Downloader
2008-08-31 06:38 --------- d-----w C:\Program Files\iolo
2008-08-23 10:52 --------- d-----w C:\Program Files\ALJAWAL
2008-08-19 09:20 --------- d-----w C:\Program Files\Java
2008-08-19 09:20 --------- d-----w C:\Program Files\Common Files\Java
2008-08-11 08:40 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2008-08-11 08:24 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2008-08-11 08:23 --------- d-----w C:\Program Files\Microsoft IntelliType Pro
2008-08-09 11:41 --------- d-----w C:\Program Files\Folderico
2008-07-19 08:18 --------- d-----w C:\Program Files\Mobily.ws
2008-07-13 09:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-13 08:59 --------- d-----w C:\Program Files\Pegasys Inc
2008-07-13 08:58 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-09 05:21 --------- d-----w C:\Program Files\Unlocker
2008-07-08 09:42 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-29 09:37 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-06-29 09:37 172,032 ------w C:\WINDOWS\Setup1.exe
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:09 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-08 11:05 16,384 ----a-w C:\WINDOWS\system32\msagnts.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [06/04/2008 02:21 PM 171448]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [03/26/2008 06:41 PM 1232896]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [04/16/2008 12:53 PM 1079808]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 05:42 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [05/08/2007 12:43 AM 702072]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [01/31/2003 04:49 PM 98304]
"DrvLsnr"="C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe" [05/28/2002 08:37 AM 69632]
"AeXAgentLogon"="C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe" [03/28/2007 03:58 AM 143360]
"USB Antivirus"="C:\Program Files\USB Disk Security\USBGuard.exe" [05/18/2008 02:41 PM 798720]
"Sonic PDF Print Dispatcher"="C:\WINDOWS\system32\iTechPrn.exe" [11/05/2007 10:51 AM 69632]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [04/17/2004 12:41 PM 196608]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [04/13/2004 06:07 AM 69632]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [08/31/2007 10:13 PM 988584]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [08/31/2007 10:01 PM 1037736]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe" [09/28/2004 08:26 PM 32881]
"bacstray"="BacsTray.exe" [03/06/2003 11:33 AM 98304 C:\WINDOWS\system32\BacsTray.exe]
"NS Agnt"="msagnts.exe" [06/08/2008 02:05 PM 16384 C:\WINDOWS\system32\msagnts.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [04/14/2008 05:42 AM 110592 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 05:42 AM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="C:\WINDOWS\Installer\TSClientMsiTrans\tscuinst.vbs" [10/30/2007 03:36 PM 13801]
"TSClientAXDisabler"="C:\WINDOWS\Installer\TSClientMsiTrans\tscdsbl.bat" [01/18/2008 08:43 PM 2247]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [7/2/2008 8:51:56 AM 106560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.voxacm150"= vct32150.acm
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\
0\
0]
"Script"=Add(Altiris)ToLocalAdminGroup.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-534540381-901058990-56781596-3381\Scripts\Logon\
0\
0]
"Script"=Expiration.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Golden Al-Wafi Translator]
--a------ 01/21/2002 02:47 PM 688128 C:\Program Files\Golden Al-Wafi Translator\Golden Al-Wafi Translator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 04/14/2008 05:42 AM 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12345:TCP"= 12345:TCP:Trend Micro OfficeScan Listener
R1 CCDevice;CCDevice;C:\WINDOWS\system32\drivers\CCDevice.sys [03/23/2005 07:14 PM 9216]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [02/01/2008 03:17 PM 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [02/01/2008 03:17 PM 8320]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-zyz1 - c:\zyz_auto_killer\run2.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://my.saudi.net.sa/
R0 -: HKCU-Main,Search Page = hxxp://www.google.com
R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie
R1 -: HKCU-Internet Settings,ProxyServer = proxy.stc.com.sa:8080
R1 -: HKCU-Internet Settings,ProxyOverride = local;<local>
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 -: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} - hxxp://bss08.stc.com.sa:7778/forms/jinitiator/jinit.exe
O16 -: {CAFECAFE-0013-0001-0028-ABCDEFABCDEF}
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-03 10:52:06
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 09/03/2008 10:53:15
ComboFix-quarantined-files.txt 2008-09-03 07:53:10
Pre-Run: 22,866,599,936 bytes free
Post-Run: 22,859,046,912 bytes free
129