ComboFix 09-06-12.02 - USER 06/13/2009 1:04.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.2940.2523 [GMT 3:00]
Running from: D:\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\recycler\S-1-5-21-9294811633-1765901151-991737872-3299\hod.exe
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\nmdfgds1.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
((((((((((((((((((((((((( Files Created from 2009-05-12 to 2009-06-12 )))))))))))))))))))))))))))))))
.
2009-06-12 21:52 . 2009-06-12 21:52 -------- d-----w- c:\program files\Trend Micro
2009-06-12 21:14 . 2009-03-30 07:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-12 21:14 . 2009-02-13 09:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-06-12 21:14 . 2009-02-13 09:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-06-12 21:14 . 2009-06-12 21:14 -------- d-----w- c:\program files\Avira
2009-06-12 21:14 . 2009-06-12 21:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-06-09 01:13 . 2009-03-24 13:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-08 21:04 . 2007-10-23 06:27 110592 ----a-w- c:\documents and settings\USER\Application Data\U3\temp\cleanup.exe
2009-06-08 21:03 . 2008-05-02 07:41 3493888 ---ha-w- c:\documents and settings\USER\Application Data\U3\temp\Launchpad Removal.exe
2009-06-08 21:02 . 2009-06-08 21:04 -------- d-----w- c:\documents and settings\USER\Application Data\U3
2009-06-08 15:11 . 2009-06-09 00:29 -------- d-----w- c:\documents and settings\USER\Application Data\MessengerDiscovery 2
2009-06-06 10:26 . 2009-06-12 02:44 -------- d-----w- c:\documents and settings\USER\Local Settings\Application Data\Adobe
2009-06-06 10:26 . 2009-06-12 02:43 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-05 12:04 . 2008-03-14 07:31 100096 ----a-w- c:\windows\system32\drivers\br3gmdm.sys
2009-06-05 12:04 . 2009-06-05 12:04 -------- d-----w- c:\program files\BandRich
2009-06-05 11:40 . 2009-06-05 11:40 -------- d--h--w- c:\windows\PIF
2009-06-01 22:58 . 2009-06-01 22:58 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-01 22:57 . 2009-06-01 22:57 152576 ----a-w- c:\documents and settings\USER\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-01 22:54 . 2009-06-01 22:54 -------- d-----w- c:\windows\Sun
2009-06-01 17:28 . 2009-06-01 17:28 -------- d--h--w- c:\windows\$hf_mig$
2009-06-01 17:19 . 2009-06-01 17:19 75376 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\sgc15.exe
2009-06-01 17:19 . 2009-06-09 21:50 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-06-01 17:19 . 2009-06-09 21:50 -------- d-----w- c:\program files\NOS
2009-05-31 20:08 . 2009-05-31 20:08 667976 ----a-w- c:\windows\system32\360x180° Mekan.scr
2009-05-31 20:08 . 2009-05-31 20:08 -------- d-----w- c:\windows\system32\mekanlar
2009-05-31 20:08 . 2009-05-31 20:08 4096 ----a-w- c:\windows\d3dx.dat
2009-05-28 16:37 . 2009-05-28 16:37 -------- d-----w- c:\program files\Kaspersky Lab
2009-05-27 11:16 . 2001-08-17 10:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-05-27 11:16 . 2001-08-17 10:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-05-27 11:16 . 2001-08-17 11:02 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-05-27 11:16 . 2001-08-17 11:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-05-27 09:52 . 2009-05-26 21:08 5167952 ----a-w- c:\program files\MsgPlusLive-481.exe
2009-05-27 09:49 . 2009-05-27 11:15 -------- d-----w- c:\windows\SxsCaPendDel
2009-05-27 09:35 . 2009-06-07 21:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-05-27 09:32 . 2009-06-10 19:04 -------- d-----w- c:\program files\Circl Developement
2009-05-27 09:32 . 2009-05-27 09:55 -------- d-----w- c:\program files\Messenger Plus! Live
2009-05-27 09:32 . 2009-05-27 09:32 -------- d-----w- c:\program files\Windows Live
2009-05-27 09:29 . 2009-06-11 23:33 -------- d-----w- c:\documents and settings\USER\Contacts
2009-05-27 09:28 . 2009-06-08 15:10 -------- d-----w- c:\program files\MSN Messenger
2009-05-26 20:56 . 2009-06-08 21:19 -------- d-----w- c:\program files\Web Publish
2009-05-26 19:04 . 2009-05-26 19:04 -------- d-----w- c:\documents and settings\USER\Application Data\vlc
2009-05-26 19:04 . 2009-05-26 19:04 -------- d-s---w- c:\documents and settings\USER\UserData
2009-05-26 19:04 . 2009-05-29 00:33 -------- d-----w- c:\documents and settings\USER\Application Data\dvdcss
2009-05-26 19:04 . 2009-05-26 19:04 -------- d-----w- c:\documents and settings\USER\Application Data\GRETECH
2009-05-26 19:04 . 2009-05-26 19:04 -------- d-----w- c:\documents and settings\USER\Application Data\Media Player Classic
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 22:58 . 2009-05-26 04:20 -------- d-----w- c:\program files\Java
2009-05-31 13:43 . 2009-05-26 04:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-27 09:31 . 2009-05-26 04:03 99496 ----a-w- c:\documents and settings\USER\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-26 05:36 . 2009-05-26 05:36 -------- d-----w- c:\documents and settings\All Users\Application Data\TOSHIBA
2009-05-26 05:02 . 2009-05-26 04:30 -------- d-----w- c:\program files\TOSHIBA
2009-05-26 05:00 . 2009-05-26 05:00 -------- d-----w- c:\program files\REALTEK RTL8187B Wireless LAN Driver
2009-05-26 05:00 . 2009-05-26 04:18 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-26 04:49 . 2009-05-26 04:49 -------- d-----w- c:\program files\Synaptics
2009-05-26 04:35 . 2009-05-26 04:35 -------- d-----w- c:\program files\Camera Assistant Software for Toshiba
2009-05-26 04:31 . 2009-05-26 04:31 -------- d-----w- c:\documents and settings\USER\Application Data\InstallShield
2009-05-26 04:30 . 2009-05-26 04:30 -------- d-----w- c:\program files\ltmoh
2009-05-26 04:28 . 2009-05-26 04:28 -------- d-----w- c:\program files\Realtek
2009-05-26 04:28 . 2009-05-26 04:28 315392 ----a-w- c:\windows\HideWin.exe
2009-05-26 04:28 . 2009-05-26 04:18 -------- d-----w- c:\program files\Common Files\InstallShield
2009-05-26 04:26 . 2009-05-26 04:26 -------- d-----w- c:\program files\Intel
2009-05-26 04:20 . 2009-05-26 04:20 -------- d-----w- c:\program files\Common Files\Java
2009-05-26 04:20 . 2009-05-26 04:20 2232 ----a-w- c:\windows\java\Packages\Data\Z1NRPNNH.DAT
2009-05-26 04:20 . 2009-05-26 04:20 155995 ----a-w- c:\windows\java\Packages\M5V33HBD.ZIP
2009-05-26 04:20 . 2009-05-26 04:20 2678 ----a-w- c:\windows\java\Packages\Data\EOE0CQBB.DAT
2009-05-26 04:20 . 2009-05-26 04:20 2678 ----a-w- c:\windows\java\Packages\Data\
0617V3TF.DAT
2009-05-26 04:20 . 2009-05-26 04:20 2678 ----a-w- c:\windows\java\Packages\Data\O9JHBFLR.DAT
2009-05-26 04:20 . 2009-05-26 04:20 2678 ----a-w- c:\windows\java\Packages\Data\CSCI97XZ.DAT
2009-05-26 04:20 . 2009-05-26 04:20 2678 ----a-w- c:\windows\java\Packages\Data\7H7HZFX3.DAT
2009-05-26 04:19 . 2009-05-26 04:19 -------- d-----w- c:\program files\GRETECH
2009-05-26 04:19 . 2009-05-26 04:19 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-05-26 04:19 . 2009-05-26 04:19 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-05-26 04:18 . 2009-05-26 04:18 -------- d-----w- c:\program files\CyberLink
2009-05-26 04:18 . 2009-05-26 04:16 -------- d-----w- c:\program files\mpegable
2009-05-26 04:17 . 2009-05-26 04:17 -------- d-----w- c:\program files\Common Files\xing shared
2009-05-26 04:17 . 2009-05-26 04:17 -------- d-----w- c:\program files\Common Files\Real
2009-05-26 04:17 . 2009-05-26 04:17 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-05-26 04:17 . 2009-05-26 04:17 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-05-26 04:17 . 2009-05-26 04:17 -------- d-----w- c:\program files\Real
2009-05-26 04:16 . 2009-05-26 04:16 -------- d-----w- c:\program files\VideoLAN
2009-05-26 04:16 . 2009-05-26 04:16 47104 ------w- c:\windows\AKDeInstall.exe
2009-05-26 04:16 . 2009-05-26 04:16 -------- d-----w- c:\program files\Microsoft Works
2009-05-26 04:16 . 2009-05-26 04:16 -------- d-----w- c:\program files\MSBuild
2009-05-26 04:14 . 2009-05-26 04:14 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-05-26 04:07 . 2009-05-26 03:57 166455 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-26 03:58 . 2009-05-26 03:58 -------- d-----w- c:\program files\microsoft frontpage
2009-05-26 03:54 . 2009-05-26 03:54 21640 ----a-w- c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-05-23 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-26 185872]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-09-18 29696]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-09-29 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-01 148888]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2008-05-27 360448]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-31 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-31 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-31 141848]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2008-04-29 417792]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2007-05-11 143360]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-31 1024000]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2008-12-19 83336]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-07-31 16860672]
"TFncKy"="TFncKy.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-05-23 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2008-12-18 2360648]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [13/06/2009 12:14 ص 108289]
R2 BandLuxe_Service;BandLuxe Service;c:\program files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe [03/06/2008 10:12 ص 87264]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [26/05/2009 07:30 ص 5888]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [26/05/2009 07:33 ص 110080]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\drivers\br3gmdm.sys [05/06/2009 03:04 م 100096]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - SSMDRV
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Settings,ProxyServer = proxy.ksu.edu.sa:8080
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-13 01:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\CF5001.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
c:\program files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe
.
**************************************************************************
.
Completion time: 2009-06-12 1:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-12 22:10
Pre-Run: 63,270,133,760 bytes free
Post-Run: 63,720,472,576 bytes free
196