ComboFix 09-05-08.03 - ASD-1990 05/09/2009 8:37.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.503.206 [GMT -7:00]
Running from: c:\documents and settings\ASD-1990\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Outdated)
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Bifrost
c:\windows\regedit.com
c:\windows\system32\taskmgr.com
.
((((((((((((((((((((((((( Files Created from 2009-04-09 to 2009-05-09 )))))))))))))))))))))))))))))))
.
2009-05-09 14:39 . 2009-05-09 14:39 270400 ----a-w c:\windows\eins8966.dll
2009-05-08 21:19 . 2009-05-08 21:19 0 ----a-w C:\svacm.exe
2009-05-08 15:52 . 2009-05-08 15:52 -------- d-----w c:\program files\Trend Micro
2009-05-06 13:57 . 2009-05-06 13:57 -------- d-----w c:\documents and settings\ASD-1990\Application Data\CyberScrub
2009-05-06 13:57 . 2009-05-06 13:57 -------- d-----w c:\documents and settings\ASD-1990\Application Data\cleaner
2009-05-05 17:46 . 2009-05-06 11:16 36793 ----a-w c:\windows\krx-642.dat
2009-05-05 17:46 . 2009-05-05 17:46 -------- d-----w c:\program files\Kristanix
2009-05-05 07:17 . 2004-08-04 01:07 135680 ----a-w c:\windows\system32\T.COM
2009-05-05 07:17 . 2004-08-04 01:07 146432 ----a-w c:\windows\R.COM
2009-05-05 06:34 . 2009-05-05 06:34 -------- d-----w c:\documents and settings\ASD-1990\Local Settings\Application Data\Downloaded Installations
2009-05-04 17:11 . 2009-05-04 17:11 -------- d-----w c:\program files\VS Revo Group
2009-05-04 12:58 . 2009-05-04 13:08 -------- d-----w c:\documents and settings\ASD-1990\Application Data\Desktopicon
2009-05-04 12:58 . 2009-05-04 13:08 -------- d-----w c:\program files\Unlocker
2009-05-04 11:13 . 2009-05-04 11:13 -------- d-----w c:\documents and settings\ASD-1990\Application Data\URSoft
2009-05-04 11:13 . 2009-05-06 13:27 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-04 11:13 . 2009-05-04 11:22 -------- d-----w c:\program files\Your Uninstaller 2008
2009-05-04 10:52 . 2009-05-05 06:22 -------- d-----w c:\documents and settings\ASD-1990\Application Data\zzMicroWorld_Anti_Virus
2009-05-04 10:51 . 2009-05-04 10:51 -------- d-----w C:\mcafeee
2009-05-03 07:00 . 2009-05-03 07:00 410984 ----a-w c:\windows\system32\deploytk.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-03 07:00 . 2009-01-08 00:24 -------- d-----w c:\program files\Java
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-23 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2005-12-01 458752]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-18 53248]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-07-22 159744]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-09-18 29696]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-09-30 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-03 148888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-10-07 278528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-08 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-08 185896]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-23 80896]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SoundMan.exe [2006-07-22 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-11-1 576104]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Mobily Connect Card\\Mobily Connect Card.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [06/02/2009 03:23 م 106208]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [06/02/2009 03:24 م 93336]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [06/02/2009 03:23 م 727720]
R3 WsAudioDevice_400;WsAudioDevice_400;c:\windows\system32\drivers\WsAudioDevice_400.sys [29/01/2009 10:21 ص 16640]
S3 FXDrv32;FXDrv32;\??\e:\fxdrv32.sys --> e:\FXDrv32.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9da05908-ed61-11dd-a440-000fb0f3334b}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9da0590c-ed61-11dd-a440-000fb0f3334b}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe08c630-ed99-11dd-a442-000fb0f3334b}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe08c631-ed99-11dd-a442-000fb0f3334b}]
\Shell\AutoRun\command - F:\AutoRun.exe
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-09 08:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-05-09 8:40
ComboFix-quarantined-files.txt 2009-05-09 15:39
Pre-Run: 30,788,685,824 bytes free
Post-Run: 30,867,546,112 bytes free
133