ComboFix 09-05-03.6 - user 05/06/2009 21:46.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.479.193 [GMT 3:00]
Running from: c:\documents and settings\user\سطح المكتب\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Outdated)
FW: McAfee Personal Firewall *enabled*
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\setup.exe
c:\windows\system32\kakle.dll
c:\windows\system32\swfDShare.dll
c:\windows\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-06 to 2009-05-06 )))))))))))))))))))))))))))))))
.
2009-05-06 18:27 . 2009-05-06 18:27 -------- d-----w c:\program files\Trend Micro
2009-05-05 15:24 . 2009-05-05 15:24 -------- d-----w c:\program files\WinSWF Extractor
2009-05-04 10:38 . 2009-05-04 10:38 -------- d-----w c:\program files\clue-by-4.org
2009-05-03 21:16 . 2009-05-03 21:16 -------- d-----w c:\documents and settings\user\Application Data\Kana Solution
2009-05-03 21:16 . 2009-05-03 21:16 -------- d-----w c:\program files\DynDNS Updater
2009-05-03 20:11 . 2009-05-03 20:11 -------- d-----w c:\program files\No-IP
2009-04-29 14:37 . 2006-08-30 03:24 5214208 ----a-w c:\windows\system32\vistaui.exe
2009-04-29 14:37 . 2005-09-21 02:42 382976 ----a-w c:\windows\system32\Vista.scr
2009-04-29 14:37 . 2005-12-10 22:53 720412 ----a-w c:\windows\system32\MGB_ScreenSaver.scr
2009-04-29 14:37 . 2009-04-29 14:37 -------- d-----w c:\program files\LClock
2009-04-29 14:37 . 2006-11-22 18:02 413518 ----a-w c:\windows\system32\vimc.exe
2009-04-29 14:33 . 2009-04-29 14:37 -------- d-----w c:\windows\system32\VITrans
2009-04-29 14:32 . 2004-12-19 20:00 111104 ----a-w c:\windows\system32\Uharc.exe
2009-04-29 14:32 . 2006-02-26 17:43 19968 ----a-w c:\windows\system32\reico.exe
2009-04-29 14:32 . 1999-12-10 21:45 8636 ----a-w c:\windows\system32\modifype.exe
2009-04-29 14:32 . 2001-10-01 11:51 69632 ----a-w c:\windows\system32\moveex.exe
2009-04-29 14:32 . 2005-05-18 08:43 81920 ----a-w c:\windows\system32\closeapp.exe
2009-04-29 14:32 . 2009-04-29 14:39 -------- d-----w C:\VTPFiles
2009-04-22 19:54 . 2009-04-30 15:22 -------- d-----w c:\documents and settings\user\Local Settings\Application Data\WMTools Downloaded Files
2009-04-22 19:27 . 2005-05-19 00:17 40960 ----a-w c:\windows\system32\osenxpsuite2005.dll
2009-04-22 19:27 . 2009-04-22 19:27 -------- d-----w c:\program files\Ozone
2009-04-22 10:23 . 2009-04-22 10:23 -------- d-----w c:\documents and settings\user\Local Settings\Application Data\Identities
2009-04-22 10:22 . 2009-04-22 12:34 -------- d-----w c:\program files\RegistryFix7
2009-04-21 09:27 . 2009-04-21 09:27 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-04-20 10:38 . 2009-04-20 10:38 -------- d-----w c:\windows\system32\LogFiles
2009-04-20 09:40 . 2009-04-20 09:40 21035 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-04-20 09:40 . 2009-04-20 09:40 -------- d-----w c:\windows\OPTIONS
2009-04-20 09:40 . 2007-07-18 08:40 264576 ------r c:\windows\system\rtl8187B.sys
2009-04-20 09:39 . 2007-08-02 10:00 38144 ----a-w c:\windows\system32\drivers\EAPPkt.sys
2009-04-20 09:39 . 2009-04-20 09:39 -------- d-----w c:\windows\system32\REALTEK USB Wireless LAN Driver and Utility
2009-04-20 09:39 . 2009-04-20 09:39 -------- d-----w c:\program files\REALTEK
2009-04-20 09:39 . 2009-04-20 09:39 -------- d-----w c:\documents and settings\user\Application Data\InstallShield
2009-04-20 09:39 . 2007-07-18 08:40 264576 ----a-r c:\windows\system32\drivers\RTL8187B.sys
2009-04-19 15:49 . 2009-04-19 15:50 -------- d-----w c:\program files\TNT Lock computer
2009-04-18 19:46 . 2009-04-18 19:46 -------- d-----w c:\documents and settings\user\Application Data\CyberLink
2009-04-18 19:24 . 2009-04-18 19:24 -------- d-----w c:\program files\Common Files\PCSuite
2009-04-18 19:24 . 2009-04-18 19:24 -------- d-----w c:\program files\Common Files\Nokia
2009-04-18 18:06 . 2009-04-18 18:06 -------- d-----w c:\documents and settings\LocalService\Application Data\SACore
2009-04-18 18:06 . 2009-04-18 18:06 -------- d-----w c:\windows\system32\config\systemprofile\Application Data\SACore
2009-04-17 18:20 . 2009-04-22 19:30 -------- d-----w c:\program files\hp deskjet 3320 series
2009-04-17 18:20 . 2002-12-18 19:29 184386 ----a-w c:\windows\system32\hpzsnt07.dll
2009-04-17 18:19 . 2009-04-17 18:19 -------- d-----w c:\program files\Hewlett-Packard
2009-04-17 18:10 . 2009-04-29 19:08 -------- d-----w c:\documents and settings\user\Application Data\U3
2009-04-17 18:03 . 2004-08-03 20:01 25856 ----a-w c:\windows\system32\drivers\usbprint.sys
2009-04-17 08:06 . 2004-08-03 19:58 5504 ----a-w c:\windows\system32\drivers\MSTEE.sys
2009-04-17 08:06 . 2004-08-03 20:10 10880 ----a-w c:\windows\system32\drivers\NdisIP.sys
2009-04-17 08:06 . 2004-08-03 20:10 15360 ----a-w c:\windows\system32\drivers\StreamIP.sys
2009-04-17 08:06 . 2004-08-03 20:10 11136 ----a-w c:\windows\system32\drivers\SLIP.sys
2009-04-17 08:06 . 2004-08-03 20:10 19328 ----a-w c:\windows\system32\drivers\WSTCODEC.SYS
2009-04-17 08:06 . 2004-08-03 20:10 85376 ----a-w c:\windows\system32\drivers\NABTSFEC.sys
2009-04-17 08:06 . 2004-08-03 20:10 17024 ----a-w c:\windows\system32\drivers\CCDECODE.sys
2009-04-17 08:06 . 2004-08-03 21:55 53760 ----a-w c:\windows\system32\vfwwdm32.dll
2009-04-17 08:06 . 2009-04-17 08:06 13824 ----a-w c:\windows\system32\drivers\splitcam.sys
2009-04-16 20:08 . 2004-08-03 20:08 25600 ----a-w c:\windows\system32\drivers\usbser.sys
2009-04-16 20:08 . 2006-10-08 18:51 23856 ----a-w c:\windows\system32\spupdsvc.exe
2009-04-16 17:47 . 2009-04-16 17:47 -------- d-s---w c:\documents and settings\user\UserData
2009-04-16 17:43 . 2009-04-16 17:43 -------- d-----w c:\documents and settings\user\Application Data\Media Player Classic
2009-04-16 17:40 . 2009-04-16 17:40 -------- d-----w c:\program files\Crazy Browser
2009-04-16 17:23 . 2009-04-16 20:09 -------- d-----w c:\documents and settings\user\Application Data\PC Suite
2009-04-16 17:22 . 2009-04-16 17:22 -------- d-----w c:\documents and settings\All Users\Application Data\PC Suite
2009-04-16 17:22 . 2009-04-18 19:25 -------- d-----w c:\documents and settings\user\Application Data\Nokia
2009-04-16 17:18 . 2007-09-17 12:53 21632 ----a-w c:\windows\system32\drivers\pccsmcfd.sys
2009-04-16 17:18 . 2009-04-16 17:18 -------- d-----w c:\program files\PC Connectivity Solution
2009-04-16 17:18 . 2008-05-07 04:38 8064 ----a-w c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-04-16 17:18 . 2008-06-06 06:24 8064 ----a-w c:\windows\system32\drivers\usbser_lowerflt.sys
2009-04-16 17:18 . 2008-05-07 04:38 20864 ----a-w c:\windows\system32\drivers\ccdcmbo.sys
2009-04-16 17:18 . 2008-05-07 04:38 17536 ----a-w c:\windows\system32\drivers\ccdcmb.sys
2009-04-16 17:18 . 2008-05-07 04:38 659968 ----a-w c:\windows\system32\nmwcdcocls.dll
2009-04-16 17:18 . 2008-05-07 04:39 1419232 ----a-w c:\windows\system32\wdfcoinstaller01005.dll
2009-04-16 17:18 . 2008-05-07 04:38 90624 ----a-w c:\windows\system32\nmwcdcls.dll
2009-04-16 17:18 . 2009-04-18 19:24 -------- d-----w c:\program files\Nokia
2009-04-16 17:17 . 2009-04-16 17:17 -------- d-----w c:\documents and settings\All Users\Application Data\Installations
2009-04-16 16:50 . 2009-04-16 16:50 -------- d-----w c:\program files\iColorFolder
2009-04-16 16:47 . 2009-04-26 16:42 -------- d-----w c:\documents and settings\user\Application Data\Paltalk
2009-04-16 16:47 . 2009-04-16 16:47 -------- d-----w c:\windows\PaltalkScene
2009-04-16 16:47 . 2009-04-16 16:48 -------- d-----w c:\program files\Paltalk Messenger
2009-04-16 16:02 . 2009-04-22 17:41 -------- d-----w c:\documents and settings\user\Contacts
2009-04-16 15:40 . 2009-04-16 15:40 -------- d-----w C:\Fraps
2009-04-16 15:37 . 2005-05-31 19:34 114688 ------w c:\windows\system32\fppr232.dll
2009-04-16 15:37 . 2005-05-31 19:32 286720 ------w c:\windows\system32\fppmon2.dll
2009-04-16 15:37 . 2002-10-25 02:17 65536 ----a-w c:\windows\system32\Crypserv.exe
2009-04-16 15:37 . 1999-06-18 21:49 165888 ----a-w c:\windows\Ckconfig.exe
2009-04-16 15:37 . 1995-07-04 18:33 11776 ----a-w c:\windows\Ckrfresh.exe
2009-04-16 15:37 . 1996-05-03 15:36 18432 ----a-w c:\windows\Setup_ck.dll
2009-04-16 15:37 . 1996-05-03 17:21 27648 ----a-r c:\windows\Setup_ck.exe
2009-04-16 15:36 . 2009-04-23 21:48 -------- d-----w c:\program files\Kelk 2000
2009-04-16 15:35 . 2009-05-05 21:53 -------- d-----w c:\program files\CamStudio
2009-04-16 15:35 . 2009-04-16 15:35 -------- d-----w c:\program files\SplitCam
2009-04-16 15:34 . 2009-05-01 20:58 -------- d-----w c:\documents and settings\user\Local Settings\Application Data\Google
2009-04-16 15:34 . 2009-05-06 14:40 -------- d-----w c:\program files\Youtube Downloader HD
2009-04-16 15:33 . 2009-04-16 15:33 -------- d-----w c:\program files\Common Files\xing shared
2009-04-16 15:32 . 2009-05-01 14:33 -------- d-----w c:\program files\Google
2009-04-16 15:27 . 2009-04-16 15:27 -------- d-----w c:\documents and settings\user\Application Data\AntsSoft
2009-04-16 15:27 . 2009-04-16 15:28 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-16 15:26 . 2009-04-16 15:27 -------- d-----w c:\program files\SWFText
2009-04-16 15:21 . 2001-08-17 11:02 9600 ----a-w c:\windows\system32\drivers\hidusb.sys
2009-04-16 14:48 . 2009-04-17 11:30 -------- d-----w c:\documents and settings\user\Application Data\BSplayer PRO
2009-04-16 14:48 . 2009-04-16 14:48 -------- d-----w c:\program files\Webteh
2009-04-16 14:43 . 2009-04-30 15:10 -------- d-----w c:\program files\SWiSHmax
2009-04-16 14:03 . 2009-04-16 14:03 -------- d-----w c:\documents and settings\LocalService\سطح المكتب
2009-04-16 14:03 . 2009-04-19 09:02 -------- d-----w c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-04-16 14:02 . 2007-11-22 03:44 33832 ----a-w c:\windows\system32\drivers\mferkdk.sys
2009-04-16 14:02 . 2007-12-02 09:51 40488 ----a-w c:\windows\system32\drivers\mfesmfk.sys
2009-04-16 14:02 . 2007-11-22 03:44 35240 ----a-w c:\windows\system32\drivers\mfebopk.sys
2009-04-16 14:02 . 2007-11-22 03:44 79304 ----a-w c:\windows\system32\drivers\mfeavfk.sys
2009-04-16 14:02 . 2007-11-22 03:44 201320 ----a-w c:\windows\system32\drivers\mfehidk.sys
2009-04-16 14:02 . 2007-07-13 06:20 113952 ----a-w c:\windows\system32\drivers\Mpfp.sys
2009-04-16 14:02 . 2009-04-16 14:02 -------- d-----w c:\program files\McAfee.com
2009-04-16 14:02 . 2009-04-16 14:02 -------- d-----w c:\program files\Common Files\McAfee
2009-04-16 14:01 . 2009-04-19 09:01 -------- d-----w c:\program files\McAfee
2009-04-16 14:01 . 2009-04-18 18:03 -------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2009-04-16 08:39 . 2009-04-16 08:39 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-04-16 08:37 . 2009-04-20 10:34 -------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-04-16 08:36 . 2009-04-16 08:36 -------- d-----w c:\windows\speech
2009-04-16 08:36 . 2009-04-16 08:36 -------- d-----w c:\program files\Golden Al-Wafi Translator
2009-04-16 08:36 . 2009-04-16 08:36 172032 ------w c:\windows\Setup1.exe
2009-04-16 08:36 . 2009-04-16 08:36 73216 ----a-w c:\windows\ST6UNST.EXE
2009-04-16 08:33 . 2009-04-17 07:26 -------- d-----w c:\program files\Circle Developement
2009-04-16 08:33 . 2009-04-17 08:03 -------- d-----w c:\program files\Messenger Plus! Live
2009-04-16 08:33 . 2009-04-16 08:33 -------- d-----w c:\program files\Windows Live
2009-04-16 08:32 . 2007-09-04 14:56 164352 ----a-w c:\windows\system32\unrar.dll
2009-04-16 08:32 . 2004-01-25 14:18 217088 ----a-w c:\windows\system32\yv12vfw.dll
2009-04-16 08:32 . 2007-07-25 11:24 1559040 ----a-w c:\windows\system32\xvidcore.dll
2009-04-16 08:32 . 2007-03-10 09:51 282624 ----a-w c:\windows\system32\xvidvfw.dll
2009-04-16 08:32 . 2007-09-28 14:07 3596288 ----a-w c:\windows\system32\qt-dx331.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-01 20:59 . 2009-04-22 19:28 2846720 ----a-w c:\windows\system32\ALOAudioCompress3.dll
2009-05-01 20:59 . 2009-04-22 19:28 778240 ----a-w c:\windows\system32\ALOAudioCompress2.dll
2009-04-29 14:42 . 2009-04-15 19:02 333296 ----a-w c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-29 14:33 . 2004-08-04 07:55 218624 ----a-w c:\windows\system32\uxtheme.dll
2009-04-22 19:28 . 2009-04-22 19:28 344064 ----a-w c:\windows\system32\dkll.dll
2009-04-16 20:08 . 2009-04-16 20:08 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2009-04-16 20:08 . 2009-04-16 20:08 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-04-16 19:05 . 2009-04-15 18:56 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-16 17:18 . 2009-04-15 19:10 -------- d-----w c:\program files\DIFX
2009-04-16 08:35 . 2009-04-16 08:35 -------- d-----w c:\program files\مشغل الفلاش العربي
2009-04-16 08:35 . 2009-04-16 08:35 2232 ----a-w c:\windows\java\Packages\Data\VN7XJF3P.DAT
2009-04-16 08:35 . 2009-04-16 08:35 155995 ----a-w c:\windows\java\Packages\Y4TJFB33.ZIP
2009-04-16 08:35 . 2009-04-16 08:35 2678 ----a-w c:\windows\java\Packages\Data\GEZF77HB.DAT
2009-04-16 08:35 . 2009-04-16 08:35 2678 ----a-w c:\windows\java\Packages\Data\GANTJNNL.DAT
2009-04-16 08:35 . 2009-04-16 08:35 2678 ----a-w c:\windows\java\Packages\Data\UTBRZNZH.DAT
2009-04-16 08:35 . 2009-04-16 08:35 2678 ----a-w c:\windows\java\Packages\Data\I579VTBB.DAT
2009-04-16 08:35 . 2009-04-16 08:35 2678 ----a-w c:\windows\java\Packages\Data\1VDB5ZTB.DAT
2009-04-15 19:35 . 2009-04-15 19:35 -------- d-----w c:\program files\Microsoft.NET
2009-04-15 19:35 . 2009-04-15 19:35 -------- d-----w c:\program files\Microsoft Works
2009-04-15 19:20 . 2001-09-19 11:00 39982 ----a-w c:\windows\system32\perfc001.dat
2009-04-15 19:20 . 2001-09-19 11:00 251478 ----a-w c:\windows\system32\perfh001.dat
2009-04-15 19:14 . 2009-04-15 19:14 -------- d-----w c:\program files\Motorola
2009-04-15 18:57 . 2009-04-15 18:57 -------- d-----w c:\program files\microsoft frontpage
2009-04-15 18:56 . 2001-09-19 11:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-04-15 18:54 . 2009-04-15 18:54 22144 ----a-w c:\windows\system32\emptyregdb.dat
.
------- Sigcheck -------
[-] 2004-08-04 08:08 2017792 B08E5140B07732B12E0BC1CDBFECAE4A c:\windows\system32\ntkrnlpa.exe
[7] 2004-08-04 08:08 2016768 0CBE3942657196CB871738E5D4A9DA79 c:\windows\system32\VITrans\ntkrnlpa.exe
[-] 2004-08-04 07:48 2150912 E0B16155DB89EA3298AE21271AD1812F c:\windows\system32\ntoskrnl.exe
[7] 2004-08-04 07:48 2149888 10AC039A4734D143A84763AEBACBCD89 c:\windows\system32\VITrans\ntoskrnl.exe
[-] 2004-08-04 07:56 1244672 715C4CD7C417A3528D862402D04EA240 c:\windows\explorer.exe
[7] 2004-08-04 07:56 1029632 932F97B77F2625F7FF7DFC97552548F8 c:\windows\system32\VITrans\explorer.exe
[-] 2009-02-04 14:27 1547776 6E932D21E116B51ED9D5157E31C48E33 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-08-16 5728112]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-01 39408]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-08-11 1124352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-29 638976]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-08-03 582992]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-16 185896]
"pdfFactory Pro Dispatcher v2"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [2005-05-31 483328]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-12-18 188416]
"LClock"="c:\program files\LClock\LClock.exe" [2004-09-19 65536]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2006-09-21 53248]
"VTTrayp"="VTtrayp.exe" - c:\windows\system32\VTTrayp.exe [2007-05-15 200704]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-4-16 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2009-1-28 10950144]
REALTEK USB Wireless LAN Utility.lnk - c:\program files\REALTEK\USB Wireless LAN Utility\ReStart.exe [2009-4-20 32768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):76,69,73,74,61,75,69,2e,65,78,65,00
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
S2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys [2007-08-02 38144]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-02-11 210216]
S2 RealtekUSB;RealtekUSB;c:\program files\REALTEK\USB Wireless LAN Utility\RtlService.exe [2007-07-27 36864]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2007-07-18 264576]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{27ecda51-2a8e-11de-8cbf-0016ec7bb394}]
\Shell\AutoRun\command - F:\AUTORUN.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2dea5469-2b79-11de-8cc7-0016ec7bb394}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-04-16 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-16 10:32]
2009-04-30 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-16 10:32]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: Microsoft XML Parser for Java
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-06 21:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(800)
c:\windows\system32\cscui.dll
.
Completion time: 2009-05-06 21:51
ComboFix-quarantined-files.txt 2009-05-06 18:51
Pre-Run: 33,665,482,752 bytes free
Post-Run: 34,437,419,008 bytes free
274