ComboFix 09-05-06.02 - csc 05/07/2009 8:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.1023.625 [GMT 3:00]
Running from: c:\documents and settings\csc\سطح المكتب\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\AutoRun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2009-04-07 to 2009-05-07 )))))))))))))))))))))))))))))))
.
2009-05-05 07:14 . 2009-05-05 07:14 -------- d-----w c:\program files\Trend Micro
2009-05-03 21:21 . 2009-05-03 23:31 -------- d-----w c:\program files\TuneUp Utilities 2008
2009-05-01 19:32 . 2009-05-01 19:32 56 ---ha-w c:\windows\system32\ezsidmv.dat
2009-05-01 19:26 . 2009-05-02 21:44 -------- d-----w c:\program files\Google
2009-05-01 19:26 . 2009-05-01 19:26 -------- d-----w c:\program files\Skype
2009-05-01 19:26 . 2009-05-01 19:26 -------- d-----w c:\program files\Common Files\Skype
2009-05-01 19:26 . 2009-05-01 19:26 -------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-04-29 09:39 . 2009-04-29 09:39 -------- d--h--w c:\windows\PIF
2009-04-22 22:51 . 2009-04-22 23:08 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-04-22 22:51 . 2009-04-22 23:08 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-04-22 22:51 . 2009-05-07 05:40 2738208 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-22 22:51 . 2009-05-07 05:40 270368 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-22 22:51 . 2009-04-22 22:51 -------- d-----w c:\program files\Kaspersky Lab
2009-04-22 22:51 . 2009-05-07 05:42 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-22 20:27 . 2009-04-22 20:27 -------- d-----w c:\program files\Xilisoft
2009-04-19 10:48 . 2009-04-19 10:48 -------- d-----w c:\program files\Conduit
2009-04-19 10:48 . 2009-04-19 10:48 -------- d-----w c:\program files\arab_stars
2009-04-18 12:41 . 2009-04-18 12:41 -------- d-----w c:\program files\Common Files\EZB Systems
2009-04-18 12:41 . 2009-04-18 12:41 -------- d-----w c:\program files\UltraISO
2009-04-15 20:38 . 2009-04-15 20:38 -------- d-----w c:\program files\Team JPN
2009-04-15 06:41 . 2009-04-21 06:31 -------- d-----w c:\program files\Free Internet TV
2009-04-15 05:51 . 2003-11-04 12:10 69632 ----a-w c:\windows\system32\lfgif13n.dll
2009-04-15 05:51 . 2004-05-14 13:53 401408 ----a-w c:\windows\system32\lfcmp13n.dll
2009-04-15 05:51 . 2004-01-11 23:09 206336 ----a-w c:\windows\system32\ltefx13n.dll
2009-04-15 05:51 . 2004-05-14 13:53 57344 ----a-w c:\windows\system32\lfbmp13n.dll
2009-04-15 05:51 . 2004-05-14 13:53 299008 ----a-w c:\windows\system32\ltdis13n.dll
2009-04-15 05:51 . 2004-05-14 13:53 450560 ----a-w c:\windows\system32\ltimg13n.dll
2009-04-15 05:51 . 2004-05-14 13:53 163840 ----a-w c:\windows\system32\ltfil13n.dll
2009-04-15 05:51 . 2004-05-14 13:53 462848 ----a-w c:\windows\system32\ltkrn13n.dll
2009-04-14 11:27 . 2009-04-14 12:09 -------- d-----w c:\program files\Total Video Converter
2009-04-14 11:23 . 2009-04-14 16:03 -------- d-----w c:\program files\USB Disk Security
2009-04-13 18:00 . 2009-04-13 18:00 -------- d-----w c:\program files\softphone3
2009-04-10 17:26 . 2009-04-10 17:30 -------- d-----w c:\program files\EAGLE-4.16r2
2009-04-10 17:25 . 1997-04-08 17:08 299520 ----a-w c:\windows\uninst.exe
2009-04-07 20:40 . 2001-08-17 19:36 8192 -c--a-w c:\windows\system32\dllcache\kbdkor.dll
2009-04-07 20:40 . 2001-08-17 19:36 8192 ----a-w c:\windows\system32\kbdkor.dll
2009-04-07 20:40 . 2001-08-17 19:36 8704 -c--a-w c:\windows\system32\dllcache\kbdjpn.dll
2009-04-07 20:40 . 2001-08-17 19:36 8704 ----a-w c:\windows\system32\kbdjpn.dll
2009-04-07 20:40 . 2001-08-17 11:55 5632 -c--a-w c:\windows\system32\dllcache\kbd103.dll
2009-04-07 20:40 . 2001-08-17 11:55 5632 ----a-w c:\windows\system32\kbd103.dll
2009-04-07 20:40 . 2001-08-17 11:55 6144 -c--a-w c:\windows\system32\dllcache\kbd101c.dll
2009-04-07 20:40 . 2001-08-17 11:55 6144 ----a-w c:\windows\system32\kbd101c.dll
2009-04-07 20:40 . 2001-08-17 11:55 6144 -c--a-w c:\windows\system32\dllcache\kbd101b.dll
2009-04-07 20:40 . 2001-08-17 11:55 6144 ----a-w c:\windows\system32\kbd101b.dll
2009-04-07 20:40 . 2008-04-14 18:28 6144 -c--a-w c:\windows\system32\dllcache\kbd106.dll
2009-04-07 20:40 . 2008-04-14 18:28 6144 ----a-w c:\windows\system32\kbd106.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-07 05:40 . 2009-04-22 22:51 3052 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-07 05:40 . 2009-04-22 22:51 24568 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-22 23:08 . 2008-01-29 14:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-04-18 17:53 . 2009-04-05 08:15 -------- d-----w c:\program files\Common Files\Adobe
2009-04-16 05:57 . 2009-04-06 12:22 -------- d-----w c:\program files\Golden Al-Wafi Translator
2009-04-06 22:28 . 2009-04-06 22:28 -------- d-----w c:\program files\DIFX
2009-04-06 22:12 . 2009-04-06 22:12 -------- d-----w c:\program files\Intel
2009-04-06 22:08 . 2009-04-05 07:01 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-06 21:58 . 2009-04-05 06:46 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-06 21:46 . 2001-09-19 14:00 40940 ----a-w c:\windows\system32\perfc001.dat
2009-04-06 21:46 . 2001-09-19 14:00 254130 ----a-w c:\windows\system32\perfh001.dat
2009-04-06 12:22 . 2009-04-06 12:22 73216 ----a-w c:\windows\ST6UNST.EXE
2009-04-06 12:22 . 2009-04-06 12:22 172032 ------w c:\windows\Setup1.exe
2009-04-06 12:18 . 2009-04-06 12:17 -------- d-----w c:\program files\FormatFactory
2009-04-06 12:16 . 2009-04-06 12:16 2232 ----a-w c:\windows\java\Packages\Data\VDFFTJL3.DAT
2009-04-06 12:16 . 2009-04-06 12:16 155995 ----a-w c:\windows\java\Packages\8JL7BN7X.ZIP
2009-04-06 12:16 . 2009-04-06 12:16 2678 ----a-w c:\windows\java\Packages\Data\2QOHZZD7.DAT
2009-04-06 12:16 . 2009-04-06 12:16 2678 ----a-w c:\windows\java\Packages\Data\ODJZTFN1.DAT
2009-04-06 12:16 . 2009-04-06 12:16 2678 ----a-w c:\windows\java\Packages\Data\NZNHZNT3.DAT
2009-04-06 12:16 . 2009-04-06 12:16 2678 ----a-w c:\windows\java\Packages\Data\LBLN1Z17.DAT
2009-04-06 12:16 . 2009-04-06 12:16 2678 ----a-w c:\windows\java\Packages\Data\DJHB71F1.DAT
2009-04-06 12:15 . 2009-04-06 12:15 -------- d-----w c:\program files\Windows Live
2009-04-06 12:14 . 2009-04-06 12:14 -------- d-----w c:\program files\K-Lite Codec Pack
2009-04-06 12:14 . 2009-04-06 12:13 -------- d-----w c:\program files\Yahoo!
2009-04-06 11:57 . 2009-04-06 11:55 -------- d-----w c:\program files\Common Files\Ahead
2009-04-06 11:55 . 2009-04-06 11:55 -------- d-----w c:\program files\Nero
2009-04-06 11:41 . 2009-04-06 11:31 113168 ----a-w c:\windows\hpoins07.dat
2009-04-06 11:39 . 2009-04-06 11:33 -------- d-----w c:\program files\HP
2009-04-06 11:39 . 2009-04-06 11:39 -------- d-----w c:\program files\Common Files\HP
2009-04-06 11:37 . 2009-04-06 11:37 -------- d-----w c:\program files\Hewlett-Packard
2009-04-06 11:36 . 2009-04-06 11:36 -------- d-----w c:\program files\Common Files\Hewlett-Packard
2009-04-05 08:26 . 2009-04-05 08:26 -------- d-----w c:\program files\Microsoft.NET
2009-04-05 08:18 . 2009-04-05 08:18 -------- d-----w c:\windows\Fonts\k9\Soft\117
2009-04-05 08:18 . 2009-04-05 08:14 -------- d-----w c:\windows\Fonts\k9\Soft
2009-04-05 08:17 . 2009-04-05 08:17 -------- d-----w c:\windows\Fonts\k9\Soft\189
2009-04-05 08:14 . 2009-04-05 08:14 -------- d-----w c:\windows\Fonts\k9\Soft\160
2009-04-05 08:14 . 2009-04-05 08:10 -------- d-----w c:\windows\Fonts\k9
2009-04-05 08:13 . 2009-04-05 08:13 -------- d-----w c:\program files\Common Files\xing shared
2009-04-05 08:13 . 2009-04-05 08:12 -------- d-----w c:\program files\Real
2009-04-05 08:13 . 2009-04-05 08:12 -------- d-----w c:\program files\Common Files\Real
2009-04-05 08:13 . 2009-04-05 08:13 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-04-05 08:13 . 2009-04-05 08:13 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-04-05 08:12 . 2009-04-05 08:12 -------- d-----w c:\windows\Fonts\k9\Multi\25
2009-04-05 08:12 . 2009-04-05 08:10 -------- d-----w c:\windows\Fonts\k9\Multi
2009-04-05 08:11 . 2009-04-05 08:11 -------- d-----w c:\program files\GRETECH
2009-04-05 08:11 . 2009-04-05 08:11 -------- d-----w c:\windows\Fonts\k9\Multi\18
2009-04-05 08:11 . 2009-04-05 08:10 -------- d-----w c:\program files\Common Files\COWON
2009-04-05 08:11 . 2009-04-05 08:10 -------- d-----w c:\program files\JetAudio
2009-04-05 08:10 . 2009-04-05 08:10 -------- d-----w c:\windows\Fonts\k9\Multi\20
2009-04-05 07:22 . 2009-04-05 07:22 -------- d-----w c:\program files\Motorola
2009-04-05 07:16 . 2009-04-05 07:16 26 ----a-w c:\windows\WINSTART.BAT
2009-04-05 07:16 . 2009-04-05 07:16 123 ----a-w c:\windows\TMPCPYIS.BAT
2009-04-05 07:16 . 2009-04-05 07:16 122 ----a-w c:\windows\TMPDELIS.BAT
2009-04-05 07:01 . 2009-04-05 07:01 315392 ----a-w c:\windows\HideWin.exe
2009-04-05 07:00 . 2009-04-05 07:00 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-05 06:47 . 2009-04-05 06:47 -------- d-----w c:\program files\microsoft frontpage
2009-04-05 06:46 . 2001-09-19 14:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-04-05 06:43 . 2009-04-05 06:43 22144 ----a-w c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{449c8ac4-2ac7-4bfd-bd9e-ad5c5dddc044}]
2009-04-01 11:27 2086936 ----a-w c:\program files\arab_stars\tbarab.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{449c8ac4-2ac7-4bfd-bd9e-ad5c5dddc044}"= "c:\program files\arab_stars\tbarab.dll" [2009-04-01 2086936]
[HKEY_CLASSES_ROOT\clsid\{449c8ac4-2ac7-4bfd-bd9e-ad5c5dddc044}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{449C8AC4-2AC7-4BFD-BD9E-AD5C5DDDC044}"= "c:\program files\arab_stars\tbarab.dll" [2009-04-01 2086936]
[HKEY_CLASSES_ROOT\clsid\{449c8ac4-2ac7-4bfd-bd9e-ad5c5dddc044}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 153136]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-11 4670968]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-08-16 5728112]
"IDMan"="c:\documents and settings\All Users\Documents\My Pictures\Internet Download Manager\IDMan.exe" [2009-01-23 2745776]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21882664]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-02 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 7700480]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-05 185896]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-04-22 206088]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-04-10 16861184]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave2"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\userinit.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\softphone3\\softphone3.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 05:29 م 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 06:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 05:06 م 24592]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{00b44638-2c9a-11de-a941-0019668cd2cd}]
\Shell\AutoRun\command - F:\xsozgc.exe
\Shell\explore\Command - F:\xsozgc.exe
\Shell\open\Command - F:\xsozgc.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01d7ad3f-2e56-11de-a947-0019668cd2cd}]
\Shell\AutoRun\command - F:\pnqdiz.exe
\Shell\explore\Command - F:\pnqdiz.exe
\Shell\open\Command - F:\pnqdiz.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{02de62fa-240b-11de-a914-0019668cd2cd}]
\Shell\AutoRun\command - K:\caekra.exe
\Shell\explore\Command - K:\caekra.exe
\Shell\open\Command - K:\caekra.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{02de62fc-240b-11de-a914-0019668cd2cd}]
\Shell\AutoRun\command - L:\caekra.exe
\Shell\explore\Command - L:\caekra.exe
\Shell\open\Command - L:\caekra.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{02de62fe-240b-11de-a914-0019668cd2cd}]
\Shell\AutoRun\command - K:\mwtrrx.exe
\Shell\explore\Command - K:\mwtrrx.exe
\Shell\open\Command - K:\mwtrrx.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{08af002f-21ae-11de-95d6-db72007238d8}]
\Shell\AutoPlaY\CommaND - K:\vkngi.exe
\Shell\AutoRun\command - K:\vkngi.exe
\Shell\exPlore\coMmANd - K:\vkngi.exe
\Shell\OPen\COmmaNd - K:\vkngi.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ead04be-3799-11de-a970-0019668cd2cd}]
\Shell\AutoRun\command - F:\cv22.cmd
\Shell\open\Command - F:\cv22.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ead04c3-3799-11de-a970-0019668cd2cd}]
\Shell\AutoRun\command - L:\dvkwhi.exe
\Shell\explore\Command - L:\dvkwhi.exe
\Shell\open\Command - L:\dvkwhi.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1546bf14-3a56-11de-a982-0019668cd2cd}]
\Shell\AutoRun\command - F:\mnmnfr.exe
\Shell\explore\Command - F:\mnmnfr.exe
\Shell\open\Command - F:\mnmnfr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1a26d922-22b3-11de-a905-0019668cd2cd}]
\Shell\AutoRun\command - K:\caekra.exe
\Shell\explore\Command - K:\caekra.exe
\Shell\open\Command - K:\caekra.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1a26d924-22b3-11de-a905-0019668cd2cd}]
\Shell\AutoRun\command - K:\caekra.exe
\Shell\explore\Command - K:\caekra.exe
\Shell\open\Command - K:\caekra.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{255145e6-26b1-11de-a923-0019668cd2cd}]
\Shell\AutoRun\command - K:\caekra.exe
\Shell\explore\Command - K:\caekra.exe
\Shell\open\Command - K:\caekra.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{255145eb-26b1-11de-a923-0019668cd2cd}]
\Shell\AutoRun\command - F:\ej10fkdo.bat
\Shell\open\Command - F:\ej10fkdo.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{31dd5a94-34bb-11de-a965-0019668cd2cd}]
\Shell\AutoRun\command - F:\ezofdc.exe
\Shell\explore\Command - F:\ezofdc.exe
\Shell\open\Command - F:\ezofdc.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3fec1116-29fd-11de-a939-0019668cd2cd}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3fec1117-29fd-11de-a939-0019668cd2cd}]
\Shell\AutoRun\command - L:\caekra.exe
\Shell\explore\Command - L:\caekra.exe
\Shell\open\Command - L:\caekra.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{41346cc3-2ce5-11de-a943-0019668cd2cd}]
\Shell\AutoRun\command - F:\caekra.exe
\Shell\explore\Command - F:\caekra.exe
\Shell\open\Command - F:\caekra.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{41346cc6-2ce5-11de-a943-0019668cd2cd}]
\Shell\AutoRun\command - F:\caekra.exe
\Shell\explore\Command - F:\caekra.exe
\Shell\open\Command - F:\caekra.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{498ef902-2717-11de-a925-0019668cd2cd}]
\Shell\AutoRun\command - F:\caekra.exe
\Shell\explore\Command - F:\caekra.exe
\Shell\open\Command - F:\caekra.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{502bc5f2-3589-11de-a96a-0019668cd2cd}]
\Shell\AutoRun\command - F:\jr6.com
\Shell\open\Command - F:\jr6.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53e232c5-24d8-11de-a91a-0019668cd2cd}]
\Shell\AutoRun\command - F:\733.exe
\Shell\explore\Command - F:\733.exe
\Shell\open\Command - F:\733.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{559ea126-33e0-11de-a960-0019668cd2cd}]
\Shell\AutoRun\command - F:\ezofdc.exe
\Shell\explore\Command - F:\ezofdc.exe
\Shell\open\Command - F:\ezofdc.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{74ad55f7-3473-11de-a964-0019668cd2cd}]
\shELl\AuToplAy\cOmmanD - F:\asfjj.pif
\shELl\AutoRun\command - F:\asfjj.pif
\shELl\ExpLoRe\Command - F:\asfjj.pif
\shELl\OpeN\CommaNd - F:\asfjj.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{846632c2-24d0-11de-a919-0019668cd2cd}]
\Shell\AutoRun\command - K:\qxty9be.cmd
\Shell\open\Command - K:\qxty9be.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{85ed4462-2844-11de-a930-0019668cd2cd}]
\Shell\AutoRun\command - K:\jr6.com
\Shell\open\Command - K:\jr6.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9d88771a-2c41-11de-a93f-0019668cd2cd}]
\Shell\AutoRun\command - L:\cgrayg.exe
\Shell\explore\Command - L:\cgrayg.exe
\Shell\open\Command - L:\cgrayg.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9faf7992-24ff-11de-a91c-0019668cd2cd}]
\Shell\AutoRun\command - K:\caekra.exe
\Shell\explore\Command - K:\caekra.exe
\Shell\open\Command - K:\caekra.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3af1e90-238c-11de-a910-0019668cd2cd}]
\Shell\AutoRun\command - K:\caekra.exe
\Shell\explore\Command - K:\caekra.exe
\Shell\open\Command - K:\caekra.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a9da799d-30d3-11de-a955-0019668cd2cd}]
\Shell\AutoRun\command - F:\xsozgc.exe
\Shell\explore\Command - F:\xsozgc.exe
\Shell\open\Command - F:\xsozgc.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ac78cd58-283e-11de-a92f-0019668cd2cd}]
\Shell\AutoRun\command - K:\xfjakt.exe
\Shell\explore\Command - K:\xfjakt.exe
\Shell\open\Command - K:\xfjakt.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0d595c8-2d5d-11de-a945-0019668cd2cd}]
\Shell\AutoRun\command - F:\caekra.exe
\Shell\explore\Command - F:\caekra.exe
\Shell\open\Command - F:\caekra.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ecc16be2-356d-11de-a969-0019668cd2cd}]
\Shell\AutoRun\command - F:\jr6.com
\Shell\open\Command - F:\jr6.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa3bcd93-244c-11de-a915-0019668cd2cd}]
\Shell\AutoRun\command - K:\d1vmq.exe
\Shell\open\Command - K:\d1vmq.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc79201e-28b1-11de-a931-0019668cd2cd}]
\Shell\AutoRun\command - F:\jr6.com
\Shell\open\Command - F:\jr6.com
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKLM-Explorer_Run-csrcs - c:\windows\system32\csrcs.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.yahoo.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.internetdownloadmanager.com/welcome.html
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Download all links with IDM - c:\documents and settings\All Users\Documents\My Pictures\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\documents and settings\All Users\Documents\My Pictures\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\documents and settings\All Users\Documents\My Pictures\Internet Download Manager\IEExt.htm
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-07 08:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-790525478-1788223648-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*b%?**]
@Class="Shell"
[HKEY_USERS\S-1-5-21-790525478-1788223648-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*b%?**\OpenWithList]
@Class="Shell"
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-07 8:44 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-07 05:44
Pre-Run: 5,712,416,768 bytes free
Post-Run: 5,796,757,504 bytes free
374