ComboFix 09-04-01.01 - RaYaN 04/02/2009 16:37:51.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1256.966.1025.18.478.136 [GMT 3:00]
Running from: c:\documents and settings\RaYaN\سطح المكتب\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-03-02 to 2009-04-02 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-13 19:12 --------- d-----w c:\program files\MSXML 4.0
2009-10-13 18:51 --------- d-----w c:\program files\HP
2009-04-02 13:37 --------- d-----w c:\documents and settings\RaYaN\Application Data\DMCache
2009-04-02 12:35 --------- d-----w c:\program files\Intel
2009-04-02 12:33 --------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
2009-04-02 12:32 --------- d-----w c:\program files\Common Files\Macrovision Shared
2009-04-02 12:32 --------- d-----w c:\program files\Common Files\Intel
2009-04-01 07:58 328,736 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-01 07:58 27,871,264 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-01 00:12 --------- d-----w c:\program files\LtUcx
2009-03-31 04:21 --------- d-----w c:\program files\PC Camera
2009-03-29 02:03 --------- d-----w c:\documents and settings\RaYaN\Application Data\Paltalk
2009-03-29 02:02 --------- d-----w c:\program files\Paltalk Messenger
2009-03-29 01:20 --------- d-----w c:\program files\Internet Download Manager
2009-03-28 22:19 --------- d-----w c:\program files\Trojan Remover
2009-03-28 22:16 --------- d-----w c:\documents and settings\RaYaN\Application Data\Simply Super Software
2009-03-28 22:16 --------- d-----w c:\documents and settings\All Users\Application Data\Simply Super Software
2009-03-28 02:15 --------- d-----w c:\documents and settings\RaYaN\Application Data\IDM
2009-03-24 02:16 --------- d-----w c:\program files\Java
2009-03-17 00:43 --------- d-----w c:\documents and settings\RaYaN\Application Data\U3
2009-03-13 23:57 --------- d-----w c:\program files\CEDP Stealer 6.0 for Messenger
2009-03-13 22:36 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-03-13 14:39 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-12 17:23 --------- d-----w c:\program files\Microsoft Silverlight
2009-03-03 10:28 203,776 ----a-w c:\windows\system32\clrviddc.dll
2009-03-02 23:04 --------- d-----w c:\program files\MessengerDiscovery
2009-03-02 06:15 --------- d-----w c:\documents and settings\RaYaN\Application Data\Avira
2009-03-02 02:50 --------- d-----w c:\program files\Avira
2009-03-02 02:50 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-03-01 01:34 --------- d-----w c:\program files\DVDVideoSoft
2009-03-01 01:34 --------- d-----w c:\program files\Common Files\DVDVideoSoft
2009-02-27 20:59 --------- d-----w c:\program files\Hotspot Shield
2009-02-22 00:10 --------- d-----w c:\program files\iVocalize Web Conference 4
2009-02-19 14:13 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-02-14 23:55 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2009-02-14 23:29 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2009-02-14 23:23 --------- d-----w c:\program files\Windows Installer Clean Up
2009-02-14 23:23 --------- d-----w c:\program files\MSECACHE
2009-02-14 20:10 --------- d-----w c:\program files\TechSmith
2009-02-14 20:10 --------- d-----w c:\documents and settings\All Users\Application Data\TechSmith
2009-02-14 19:57 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-02-14 18:30 155,995 ----a-w c:\windows\java\Packages\F575JB5B.ZIP
2009-02-13 15:17 --------- d-----w c:\documents and settings\RaYaN\Application Data\HP
2009-02-13 14:27 --------- d-----w c:\documents and settings\All Users\Application Data\HP
2009-02-13 14:26 --------- d-----w c:\program files\Common Files\HP
2009-02-13 14:17 --------- d-----w c:\program files\Common Files\Hewlett-Packard
2009-02-13 10:00 --------- d-----w c:\program files\Google
2009-02-12 18:15 676,224 ----a-w c:\windows\system32\OGACheckControl.dll
2009-02-10 15:08 --------- d-----w c:\program files\BandRich
2009-02-09 14:15 1,846,144 ----a-w c:\windows\system32\win32k.sys
2009-02-08 21:54 --------- d-----w c:\program files\Alwil Software
2009-02-08 21:02 --------- d-----w c:\program files\CCleaner
2009-02-08 18:20 --------- d-----w c:\program files\Messenger Plus! Live
2009-02-08 18:09 --------- d-----w c:\program files\Windows Live
2009-02-08 18:09 --------- d-----w c:\program files\Microsoft
2009-02-08 17:55 499,712 ----a-w c:\windows\system32\msvcp71.dll
2009-02-08 17:55 348,160 ----a-w c:\windows\system32\msvcr71.dll
2009-02-08 17:55 --------- d-----w c:\program files\Real
2009-02-08 17:55 --------- d-----w c:\program files\Common Files\xing shared
2009-02-08 17:55 --------- d-----w c:\program files\Common Files\Windows Live
2009-02-08 17:55 --------- d-----w c:\program files\Common Files\Real
2009-02-08 17:54 --------- d-----w c:\program files\DivX
2009-02-08 17:09 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-02-08 16:56 --------- d-----w c:\program files\InterVideo
2009-02-08 16:55 --------- d-----w c:\documents and settings\All Users\Application Data\QuickTime
2009-02-08 16:54 1,680 --sha-r c:\windows\system32\drivers\103C_HP_NTBK_HP Pavilion ze2000 (EA978EA#ABV)_YN_0Pavi_QCNF5201CVM_EU_46_I09EC_SQuanta_V34.20_BF.20_T050415_WXH2_L401_M479_J40_7Intel_8Pentium M_91.6_#090208_N10EC8139_(EA978EA#ABV)_XMOBILE_CN10_Z808624C6_2Rev 1.MRK
2009-02-08 16:54 --------- d-----w c:\program files\HPQ
2009-02-08 16:54 --------- d-----w c:\documents and settings\RaYaN\Application Data\Sonic
2009-02-08 16:53 20,576 ----a-w c:\windows\system32\drivers\pxhelp20.sys
2009-02-08 16:53 108,544 ----a-w c:\windows\system32\pxcpyi64.exe
2009-02-08 16:53 103,936 ----a-w c:\windows\system32\pxinsi64.exe
2009-02-08 16:49 --------- d-----w c:\program files\QuickTime
2009-02-08 16:49 --------- d-----w c:\program files\iTunes
2009-02-08 16:49 --------- d-----w c:\program files\iPod
2009-02-08 16:49 --------- d-----w c:\documents and settings\RaYaN\Application Data\Apple Computer
2009-02-08 16:49 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-02-08 16:47 --------- d-----w c:\program files\Common Files\InstallShield
2009-02-08 16:41 --------- d-----w c:\program files\Synaptics
2009-02-08 16:40 --------- d-----w c:\program files\CONEXANT
2009-02-08 16:38 --------- d-----w c:\program files\WIDCOMM
2009-02-08 16:22 --------- d-----w c:\program files\microsoft frontpage
2009-01-22 14:49 206,256 ----a-w c:\windows\system32\idmmbc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 03:00 PM 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [02/13/2009 01:01 PM 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [10/05/2004 07:25 PM 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [10/05/2004 07:24 PM 688218]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [06/17/2004 11:48 PM 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [05/08/2007 04:24 PM 54840]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [06/17/2004 11:43 PM 118784]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [09/17/2004 04:19 PM 290816]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [10/13/2004 05:34 PM 229438]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [06/12/2008 01:28 PM 266497]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [02/08/2009 08:09 PM 136600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 03:00 PM 15360]
c:\documents and settings\All Users\çںê، ں*§ڑ\ںé*©ںê¤\*§ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-01-01 113664]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-06-02 565309]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SlipStream
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AFProg]
--a------ 06/26/2006 05:26 AM 118784 c:\program files\Hotspot Shield\AnchorFree\ctrl\AFController.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 03/05/2009 12:44 AM 133104 c:\documents and settings\RaYaN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 08/04/2004 03:00 PM 208952 c:\windows\ime\imjp8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 06/04/2004 12:38 PM 286720 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 10/13/2004 07:24 PM 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 02/08/2009 07:49 PM 98304 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 02/13/2009 01:01 PM 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
--a------ 02/15/2009 04:53 PM 1214856 c:\program files\Trojan Remover\Trjscan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"Driver32"=
"raVe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\program files\\premieropinion\\pmropn.exe"=
R2 antivirwebservice;Avira AntiVir Premium WebGuard;c:\program files\Avira\AntiVir PersonalEdition Premium\avwebgrd.exe [2009-03-02 258305]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;c:\program files\Avira\AntiVir PersonalEdition Premium\avesvc.exe [2009-03-02 41217]
R2 BandLuxe_Service;BandLuxe Service;c:\program files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe [2008-10-03 87264]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2004-01-01 603904]
S2 AntiVirMailService;Avira AntiVir Premium MailGuard;c:\program files\Avira\AntiVir PersonalEdition Premium\avmailc.exe [2009-03-02 164097]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\drivers\br3gmdm.sys [2009-02-10 104192]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{13255ccb-3c96-11d8-b4cc-c635cd4b4e0d}]
\Shell\AutoRun\command - bd3q0qix.exe
\Shell\open\Command - bd3q0qix.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c4bbd708-128a-11de-b50a-00c09f957621}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-04-02 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [12/11/2008 11:36 PM]
2009-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1563985344-682003330-1004.job
- c:\documents and settings\RaYaN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [03/05/2009 12:44 AM]
2009-04-02 c:\windows\Tasks\HPpromotions journeysoftware.job
- c:\program files\hp\digital imaging\bin\hp promotions\journeysoftware\HPpromo.exe [04/22/2005 05:36 PM]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
MSConfigStartUp-Device Detector - DevDetect.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
LSP: c:\windows\system32\idmmbc.dll
LSP: avsda.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {3C8E8DD8-D86A-4E6D-AF37-AB3CA7FDF8CD} - hxxp://f5f9.redirectme.net/imscp/talkc38.cab
FF - ProfilePath - c:\documents and settings\RaYaN\Application Data\Mozilla\Firefox\Profiles\h8p2mimb.default\
FF - prefs.js: browser.search.selectedEngine - qtl
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sa/
FF - prefs.js: network.proxy.type - 2
FF - component: c:\documents and settings\RaYaN\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - plugin: c:\documents and settings\RaYaN\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
------- File Associations -------
.
txtfile=NOTEPAD %1
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-02 16:41:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe???????????????|?P???? ???B?????????????H<C? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1328)
c:\program files\PremierOpinion\pmls.dll
- - - - - - - > 'lsass.exe'(1792)
c:\windows\system32\idmmbc.dll
c:\windows\system32\avsda.dll
.
Completion time: 04/02/2009 16:44:04
ComboFix-quarantined-files.txt 2009-04-02 13:43:57
Pre-Run: 29,684,363,264 bytes free
Post-Run: 29,678,170,112 bytes free
258 --- E O F --- 2009-04-02 13:06:15