ComboFix 09-05-05.02 - icc 05/05/2009 23:31.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1256.966.1025.18.1013.400 [GMT 3:00]
Running from: c:\windows\system32\config\systemprofile\Desktop\مس.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Implode.dll
c:\windows\system32\MabryObj.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-05 to 2009-05-05 )))))))))))))))))))))))))))))))
.
2009-05-05 19:57 . 2009-05-05 19:57 -------- d-----w c:\program files\Trend Micro
2009-05-05 07:20 . 2009-05-05 07:20 -------- d-----w c:\program files\Circle Developemet
2009-05-02 20:44 . 2009-05-02 20:44 -------- d-----w c:\program files\Time Watch
2009-04-30 16:58 . 2009-04-30 16:58 -------- d-----w c:\windows\system32\config\systemprofile\AppData\Roaming\Media Player Classic
2009-04-30 00:52 . 2009-04-30 00:55 -------- d-----w c:\windows\system32\config\systemprofile\AppData\Local\Adobe
2009-04-30 00:51 . 2009-04-30 00:51 -------- d-----w c:\windows\system32\config\systemprofile\AppData\Roaming\TuneUp Software
2009-04-29 23:32 . 2009-03-24 13:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-04-29 23:32 . 2009-04-29 23:32 -------- d-----w c:\programdata\Avira
2009-04-29 23:32 . 2009-04-29 23:32 -------- d-----w c:\users\All Users\Avira
2009-04-29 23:32 . 2009-04-29 23:32 -------- d-----w c:\program files\Avira
2009-04-29 23:31 . 2009-04-30 17:45 -------- d-----r c:\windows\system32\config\systemprofile\Downloads
2009-04-29 23:31 . 2009-04-29 23:31 -------- d-----r c:\users\TEMP\Searches
2009-04-29 23:31 . 2009-05-05 07:12 -------- d-----r c:\windows\system32\config\systemprofile\Pictures
2009-04-29 22:49 . 2006-11-02 10:23 -------- d-----r c:\users\TEMP\Music
2009-04-29 22:49 . 2006-11-02 10:23 -------- d-----r c:\users\TEMP\Pictures
2009-04-29 22:49 . 2009-04-29 23:31 -------- d-----r c:\users\TEMP\Saved Games
2009-04-29 22:49 . 2006-11-02 10:23 -------- d-----r c:\users\TEMP\Videos
2009-04-29 22:49 . 2009-04-29 23:31 -------- d-----w c:\users\TEMP
2009-04-29 22:06 . 2009-04-29 22:06 -------- d-----w C:\Downloads
2009-04-26 17:11 . 2009-04-26 17:11 -------- d-----w c:\programdata\Nokia
2009-04-26 17:11 . 2009-04-26 17:11 -------- d-----w c:\users\All Users\Nokia
2009-04-26 05:16 . 2008-09-15 04:56 91136 ----a-w c:\windows\system32\nmwcdcls.dll
2009-04-26 05:15 . 2009-04-26 05:15 -------- d-----w c:\program files\Common Files\Nokia
2009-04-26 05:15 . 2009-04-26 05:17 -------- d-----w c:\program files\Nokia
2009-04-26 05:14 . 2009-04-26 05:14 -------- d-----w c:\programdata\Installations
2009-04-26 05:14 . 2009-04-26 05:14 -------- d-----w c:\users\All Users\Installations
2009-04-26 02:59 . 2009-04-26 02:59 2560 ----a-w c:\windows\_MSRSTRT.EXE
2009-04-26 02:49 . 2009-04-26 03:00 -------- d-----w c:\program files\Conduit
2009-04-26 02:49 . 2009-04-26 03:00 -------- d-----w c:\program files\Hotspot_Shield
2009-04-25 22:45 . 2009-04-25 22:45 -------- d-----w c:\users\icc\AppData\Roaming\JLC's Software
2009-04-25 19:11 . 2009-04-25 19:11 -------- d-----w c:\program files\JLC's Software
2009-04-24 18:52 . 2009-04-24 18:52 -------- d-----w c:\users\icc\AppData\Roaming\Moyea
2009-04-24 15:40 . 2009-05-05 18:16 -------- d-----w c:\windows\system32\config\systemprofile\Tracing
2009-04-24 15:40 . 2009-05-05 20:35 -------- d-----w c:\windows\system32\config\systemprofile\AppData\Local\Temp
2009-04-20 17:57 . 2003-06-18 14:31 17920 ----a-w c:\windows\system32\mdimon.dll
2009-04-20 15:48 . 2007-01-17 18:34 1872 ----a-w C:\ATS.reg
2009-04-20 15:48 . 2009-05-04 17:14 -------- d-----w C:\PrimerDB
2009-04-17 00:21 . 2009-04-17 00:21 -------- d-----w c:\users\icc\AppData\Local\Apps
2009-04-15 02:03 . 2009-04-29 21:53 -------- d-----w c:\users\icc\Tracing
2009-04-15 01:51 . 2009-04-15 01:51 -------- d-----w c:\program files\Microsoft Sync Framework
2009-04-15 01:50 . 2006-11-29 10:06 3426072 ----a-w c:\windows\system32\d3dx9_32.dll
2009-04-15 01:50 . 2009-04-15 01:50 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-04-15 01:47 . 2009-04-15 01:47 -------- d-----w c:\program files\Microsoft
2009-04-15 01:47 . 2009-04-15 01:47 -------- d-----w c:\program files\Windows Live SkyDrive
2009-04-15 01:47 . 2009-05-05 04:10 -------- d-----w c:\program files\Windows Live
2009-04-13 21:31 . 2009-04-13 21:31 -------- d-----r c:\windows\system32\config\systemprofile\Music
2009-04-12 02:06 . 2009-04-12 02:06 -------- d-----w C:\Total_Training
2009-04-10 21:51 . 2009-04-10 21:51 -------- d-----w c:\programdata\Atelier Web
2009-04-10 21:51 . 2009-04-10 21:51 -------- d-----w c:\users\All Users\Atelier Web
2009-04-10 21:51 . 2009-04-10 21:51 -------- d-----w c:\program files\Atelier Web
2009-04-07 21:40 . 2009-04-07 21:40 -------- d-----w c:\program files\Common Files\Windows Live
2009-04-07 18:47 . 2009-04-07 18:47 -------- d-----w c:\program files\Toshiba
2009-04-07 18:46 . 2009-01-16 08:23 -------- d-----w C:\v63001T_20081226_x32
2009-04-07 18:43 . 2009-04-07 18:43 -------- d-----w c:\program files\Windows Journal
2009-04-07 18:42 . 2009-04-07 18:42 -------- d-----w c:\windows\ehome
2009-04-07 18:42 . 2009-04-07 18:42 -------- d-----w c:\windows\system32\ar
2009-04-07 18:42 . 2009-04-07 18:43 -------- d-----w c:\windows\ar-SA
2009-04-07 18:42 . 2009-04-07 18:43 -------- d-----w c:\windows\system32\drivers\ar-SA
2009-04-07 17:23 . 2009-04-07 17:23 -------- d-----w c:\users\icc\AppData\Roaming\Media Player Classic
2009-04-07 01:12 . 2009-04-06 14:18 -------- d-----w c:\windows\Panther
2009-04-07 01:12 . 2009-04-07 01:12 -------- d-sh--w C:\Boot
2009-04-07 01:12 . 2009-04-07 01:12 -------- d-----w c:\windows\system32\OEM
2009-04-06 18:21 . 2009-04-26 09:52 -------- d-----w c:\users\icc\AppData\Local\Adobe
2009-04-06 17:01 . 2009-04-06 17:01 -------- d-----w c:\windows\system32\Lang
2009-04-06 17:01 . 2006-11-10 13:25 319456 ----a-w c:\windows\system32\difxapi.dll
2009-04-06 17:01 . 2008-02-22 07:34 920088 ----a-w c:\windows\system32\igxpun.exe
2009-04-06 17:01 . 2009-04-26 02:36 -------- d-----w C:\Intel
2009-04-06 16:20 . 2008-03-20 03:41 16480 ----a-w c:\windows\system32\rixdicon.dll
2009-04-06 16:19 . 2008-10-22 01:22 2048 ----a-w c:\windows\system32\tzres.dll
2009-04-06 16:01 . 2008-06-20 01:14 97800 ----a-w c:\windows\system32\infocardapi.dll
2009-04-06 16:01 . 2008-06-20 01:14 105016 ----a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-04-06 16:01 . 2008-06-20 01:14 622080 ----a-w c:\windows\system32\icardagt.exe
2009-04-06 16:01 . 2008-06-20 01:14 11264 ----a-w c:\windows\system32\icardres.dll
2009-04-06 16:01 . 2008-06-20 01:14 43544 ----a-w c:\windows\system32\PresentationHostProxy.dll
2009-04-06 16:01 . 2008-06-20 01:14 781344 ----a-w c:\windows\system32\PresentationNative_v0300.dll
2009-04-06 16:01 . 2008-06-20 01:14 326160 ----a-w c:\windows\system32\PresentationHost.exe
2009-04-06 15:55 . 2008-07-27 18:03 96760 ----a-w c:\windows\system32\dfshim.dll
2009-04-06 15:55 . 2008-07-27 18:03 282112 ----a-w c:\windows\system32\mscoree.dll
2009-04-06 15:55 . 2008-07-27 18:03 41984 ----a-w c:\windows\system32\netfxperf.dll
2009-04-06 15:55 . 2008-07-27 18:03 158720 ----a-w c:\windows\system32\mscorier.dll
2009-04-06 15:55 . 2008-07-27 18:03 83968 ----a-w c:\windows\system32\mscories.dll
2009-04-06 15:53 . 2008-06-26 01:45 12240896 ----a-w c:\windows\system32\NlsLexicons0007.dll
2009-04-06 15:53 . 2008-06-26 01:45 2644480 ----a-w c:\windows\system32\NlsLexicons0009.dll
2009-04-06 15:53 . 2008-06-26 03:29 801280 ----a-w c:\windows\system32\NaturalLanguage6.dll
2009-04-06 15:49 . 2008-02-29 07:14 19000 ----a-w c:\windows\system32\kd1394.dll
2009-04-06 15:49 . 2008-02-22 05:05 615992 ----a-w c:\windows\system32\ci.dll
2009-04-06 15:49 . 2008-02-29 07:11 988216 ----a-w c:\windows\system32\winload.exe
2009-04-06 15:49 . 2008-02-29 07:11 927288 ----a-w c:\windows\system32\winresume.exe
2009-04-06 15:49 . 2008-02-29 06:53 378368 ----a-w c:\windows\system32\srcore.dll
2009-04-06 15:49 . 2008-02-29 06:53 46592 ----a-w c:\windows\system32\setbcdlocale.dll
2009-04-06 15:49 . 2008-02-29 06:53 40960 ----a-w c:\windows\system32\srclient.dll
2009-04-06 15:49 . 2008-02-29 04:12 318464 ----a-w c:\windows\system32\rstrui.exe
2009-04-06 15:49 . 2008-02-29 04:12 14848 ----a-w c:\windows\system32\srdelayed.exe
2009-04-06 15:49 . 2008-02-29 06:35 6656 ----a-w c:\windows\system32\kbd106n.dll
2009-04-06 15:49 . 2008-05-10 01:33 113664 ----a-w c:\windows\system32\drivers\rmcast.sys
2009-04-06 15:48 . 2008-10-29 06:29 2927104 ----a-w c:\windows\explorer.exe
2009-04-06 15:48 . 2008-08-28 03:40 425472 ----a-w c:\windows\system32\PhotoMetadataHandler.dll
2009-04-06 15:48 . 2008-08-28 03:37 347648 ----a-w c:\windows\system32\WindowsCodecsExt.dll
2009-04-06 15:48 . 2008-08-28 03:37 712704 ----a-w c:\windows\system32\WindowsCodecs.dll
2009-04-06 15:48 . 2008-12-16 05:31 7680 ----a-w c:\windows\system32\spwmp.dll
2009-04-06 15:48 . 2008-12-16 05:31 4096 ----a-w c:\windows\system32\dxmasf.dll
2009-04-06 15:48 . 2008-12-16 03:29 8147456 ----a-w c:\windows\system32\wmploc.DLL
2009-04-06 15:48 . 2008-09-05 05:14 1191936 ----a-w c:\windows\system32\msxml3.dll
2009-04-06 15:45 . 2008-09-18 04:56 147456 ----a-w c:\windows\system32\Faultrep.dll
2009-04-06 15:45 . 2008-09-18 04:56 125952 ----a-w c:\windows\system32\wersvc.dll
2009-04-06 15:44 . 2008-11-27 04:43 268288 ----a-w c:\windows\system32\schannel.dll
2009-04-06 15:43 . 2008-06-26 03:29 565248 ----a-w c:\windows\system32\emdmgmt.dll
2009-04-06 15:43 . 2008-05-08 19:21 211968 ----a-w c:\windows\system32\drivers\mrxsmb10.sys
2009-04-06 15:43 . 2008-08-02 01:01 625152 ----a-w c:\windows\system32\drivers\dxgkrnl.sys
2009-04-06 15:43 . 2008-06-26 03:29 45056 ----a-w c:\windows\system32\dataclen.dll
2009-04-06 15:43 . 2008-05-20 02:07 148480 ----a-w c:\windows\system32\drivers\nwifi.sys
2009-04-06 15:43 . 2008-08-02 03:26 36864 ----a-w c:\windows\system32\cdd.dll
2009-04-06 15:43 . 2008-08-12 03:39 443392 ----a-w c:\windows\system32\win32spl.dll
2009-04-06 15:43 . 2008-06-23 01:59 2868736 ----a-w c:\windows\system32\mf.dll
2009-04-06 15:43 . 2008-06-23 01:59 996352 ----a-w c:\windows\system32\WMNetMgr.dll
2009-04-06 15:43 . 2008-06-23 01:58 94720 ----a-w c:\windows\system32\logagent.exe
2009-04-06 15:42 . 2008-12-16 02:42 288768 ----a-w c:\windows\system32\drivers\srv.sys
2009-04-06 15:42 . 2009-02-09 03:10 2033152 ----a-w c:\windows\system32\win32k.sys
2009-04-06 15:42 . 2008-09-18 05:09 3601464 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-04-06 15:42 . 2008-09-18 05:09 3549240 ----a-w c:\windows\system32\ntoskrnl.exe
2009-04-06 15:42 . 2008-10-21 05:25 1645568 ----a-w c:\windows\system32\connect.dll
2009-04-06 15:41 . 2008-05-08 21:59 430080 ----a-w c:\windows\system32\vbscript.dll
2009-04-06 15:41 . 2008-05-08 21:59 90112 ----a-w c:\windows\system32\wshext.dll
2009-04-06 15:41 . 2008-05-08 21:59 155648 ----a-w c:\windows\system32\wscript.exe
2009-04-06 15:41 . 2008-05-08 21:58 135168 ----a-w c:\windows\system32\cscript.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-29 23:05 . 2009-04-29 23:05 -------- d-----w c:\program files\Advanced Registry Optimizer
2009-04-29 21:00 . 2009-04-29 21:00 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-04-26 05:18 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstor.dat
2009-04-26 05:18 . 2006-11-02 10:25 51200 ----a-w c:\windows\inf\infpub.dat
2009-04-26 05:18 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstrng.dat
2009-04-20 15:45 . 2009-04-20 15:45 -------- d-----w c:\program files\NCC Education
2009-04-07 18:43 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Defender
2009-04-07 18:43 . 2006-11-02 12:35 -------- d-----w c:\program files\Microsoft Games
2009-04-07 18:43 . 2009-04-07 18:43 41018 ----a-w c:\windows\inf\PERFLIB\
0401\perfd.dat
2009-04-07 18:43 . 2009-04-07 18:43 41018 ----a-w c:\windows\inf\PERFLIB\
0401\perfc.dat
2009-04-07 18:43 . 2009-04-07 18:43 285290 ----a-w c:\windows\inf\PERFLIB\
0401\perfi.dat
2009-04-07 18:43 . 2009-04-07 18:43 285290 ----a-w c:\windows\inf\PERFLIB\
0401\perfh.dat
2009-04-07 18:43 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Collaboration
2009-04-07 18:42 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Calendar
2009-04-07 18:42 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-04-07 18:42 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Photo Gallery
2009-04-07 18:42 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Sidebar
2009-04-07 17:17 . 2009-04-07 17:17 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-04-06 16:52 . 2009-04-06 14:23 680 ----a-w c:\users\icc\AppData\Local\d3d9caps.dat
2009-04-06 16:30 . 2009-04-06 14:23 115576 ----a-w c:\users\icc\AppData\Local\GDIPFONTCACHEV1.DAT
2009-04-06 16:25 . 2006-11-02 10:25 665600 ----a-w c:\windows\inf\drvindex.dat
2009-04-06 15:25 . 2006-11-02 12:35 -------- d-----w c:\program files\MSBuild
2009-04-06 14:36 . 2009-04-06 14:36 -------- d-----w c:\program files\Moyea
2009-04-06 14:36 . 2009-04-06 14:36 2232 ----a-w c:\windows\Java\Packages\Data\5RZFXB75.DAT
2009-04-06 14:36 . 2009-04-06 14:36 155995 ----a-w c:\windows\Java\Packages\YRPF9V13.ZIP
2009-04-06 14:36 . 2009-04-06 14:36 2678 ----a-w c:\windows\Java\Packages\Data\GBHRRRBH.DAT
2009-04-06 14:36 . 2009-04-06 14:36 2678 ----a-w c:\windows\Java\Packages\Data\6NHJ3D77.DAT
2009-04-06 14:36 . 2009-04-06 14:36 2678 ----a-w c:\windows\Java\Packages\Data\SDNP7FVD.DAT
2009-04-06 14:36 . 2009-04-06 14:36 2678 ----a-w c:\windows\Java\Packages\Data\R5ZBZBJP.DAT
2009-04-06 14:36 . 2009-04-06 14:36 2678 ----a-w c:\windows\Java\Packages\Data\
0W6444UD.DAT
2009-04-06 14:35 . 2009-04-06 14:35 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-04-06 14:35 . 2009-04-06 14:35 -------- d-----w c:\program files\Real
2009-04-06 14:35 . 2009-04-06 14:35 -------- d-----w c:\program files\Winamp
2009-04-06 14:21 . 2006-11-02 12:59 1356 ----a-w c:\windows\system32\config\systemprofile\AppData\Local\d3d9caps.dat
2009-02-06 16:43 . 2009-02-06 16:43 307576 ----a-w c:\windows\WLXPGSS.SCR
2009-02-06 15:52 . 2009-02-06 15:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2008-01-21 02:57 . 2006-11-02 12:48 174 --sha-w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Time Watch"="c:\program files\Time Watch\Timewatch.exe" [2004-01-07 346182]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-21 2153472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-06 185872]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-22 133656]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2008-12-19 83336]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"StormCodec_Helper"="c:\program files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3309672945-645136108-1640263374-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{896C392E-7EAD-4B17-9C55-AC59DC6E65A4}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{CBFF16BB-D3DD-433C-98BF-619CC9176678}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{BD4EB90C-AC8F-4071-B0D7-1406C80E4D33}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{EF1B551C-1054-439D-9E71-4D9ACE7BADA8}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{12233115-51F9-4DD4-B236-2E6E414C79BA}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{64F2E923-E9EE-4A4D-A81A-2B98576D4726}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{96814180-1B79-48BA-8663-558B24045F12}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{05FE846A-2A6C-4F1F-8317-8E63105CF1E8}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{E7D492FE-626F-4773-830F-73830BA1A9C9}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{AD22BC6A-F587-4E07-B235-EAD7B956195D}c:\\program files\\jlc's software\\internet tv\\internet tv.exe"= UDP:c:\program files\jlc's software\internet tv\internet tv.exe:Internet TV
"UDP Query User{6AD222FE-B8E3-4C5F-80B5-D02CE9E2F707}c:\\program files\\jlc's software\\internet tv\\internet tv.exe"= TCP:c:\program files\jlc's software\internet tv\internet tv.exe:Internet TV
R0 OemBiosDevice;Royalty OEM Bios Extension;c:\windows\System32\drivers\royal.sys [2009-04-06 240128]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2008-02-01 138112]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2008-02-01 8320]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-04-01 108289]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
--- Other Services/Drivers In Memory ---
*Deregistered* - AFD
*Deregistered* - avgio
*Deregistered* - avgntflt
*Deregistered* - avipbb
*Deregistered* - Beep
*Deregistered* - bowser
*Deregistered* - cdfs
*Deregistered* - CLFS
*Deregistered* - Compbatt
*Deregistered* - crcdisk
*Deregistered* - DfsC
*Deregistered* - DXGKrnl
*Deregistered* - FileInfo
*Deregistered* - FltMgr
*Deregistered* - HTTP
*Deregistered* - iScsiPrt
*Deregistered* - KSecDD
*Deregistered* - lltdio
*Deregistered* - luafv
*Deregistered* - MountMgr
*Deregistered* - mpsdrv
*Deregistered* - MRxDAV
*Deregistered* - mrxsmb
*Deregistered* - mrxsmb10
*Deregistered* - mrxsmb20
*Deregistered* - Msfs
*Deregistered* - msisadrv
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NativeWifiP
*Deregistered* - NDIS
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - netbt
*Deregistered* - Npfs
*Deregistered* - nsiproxy
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PEAUTH
*Deregistered* - PptpMiniport
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - RasSstp
*Deregistered* - rdbss
*Deregistered* - RDPCDD
*Deregistered* - RDPENCDD
*Deregistered* - rspndr
*Deregistered* - secdrv
*Deregistered* - Smb
*Deregistered* - spldr
*Deregistered* - srv
*Deregistered* - srv2
*Deregistered* - srvnet
*Deregistered* - ssmdrv
*Deregistered* - swenum
*Deregistered* - Tcpip
*Deregistered* - tcpipreg
*Deregistered* - tdx
*Deregistered* - TermDD
*Deregistered* - tunmp
*Deregistered* - tunnel
*Deregistered* - umbus
*Deregistered* - VgaSave
*Deregistered* - volmgr
*Deregistered* - volmgrx
*Deregistered* - volsnap
*Deregistered* - Wanarpv6
*Deregistered* - Wdf01000
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-04-06 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 12:17]
2009-05-05 c:\windows\Tasks\User_Feed_Synchronization-{7A4B8C54-8488-4F33-8E76-69280E03E7A8}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{c95a4e8e-816d-4655-8c79-d736da1adb6d} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-05 23:35
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-05-05 23:36
ComboFix-quarantined-files.txt 2009-05-05 20:36
Pre-Run: 10,799,411,200 bytes free
Post-Run: 10,796,621,824 bytes free
352 --- E O F --- 2009-04-06 16:24