ComboFix 09-06-22.0A - S.A.H 06/23/2009 16:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.991.738 [GMT 3:00]
Running from: c:\documents and settings\S.A.H\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\الفوزان\Application Data\FunWebProducts
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd
c:\documents and settings\الفوزان\Application Data\FunWebProducts\Data\الفوزان\avatar.dat
c:\documents and settings\الفوزان\Application Data\FunWebProducts\Data\الفوزان\zbucks.dat
c:\program files\Internet Explorer\msimg32.dll
c:\windows\system32\kakle.dll
D:\Desktop.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
((((((((((((((((((((((((( Files Created from 2009-05-23 to 2009-06-23 )))))))))))))))))))))))))))))))
.
2009-06-22 19:27 . 2009-06-22 19:27 -------- d-----w- c:\documents and settings\S.A.H\Application Data\Malwarebytes
2009-06-22 19:27 . 2008-10-16 17:25 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-22 19:27 . 2008-10-16 17:25 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-22 19:27 . 2009-06-22 19:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-22 19:27 . 2009-06-22 19:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-22 18:50 . 2009-06-22 18:50 -------- d-----w- c:\program files\Trend Micro
2009-06-19 17:26 . 2009-06-19 17:26 -------- d-----w- c:\program files\Common Files\Vbox
2009-06-19 17:26 . 2001-10-26 21:16 16384 ----a-w- c:\windows\system32\FileOps.exe
2009-06-19 17:26 . 2009-06-19 17:26 -------- d-----w- c:\windows\system32\Adobe
2009-06-19 17:20 . 2009-06-19 17:20 -------- d-----w- C:\Adobe Illustrator Installer
2009-05-30 11:21 . 2009-05-30 11:21 -------- d-----w- c:\program files\Nufsoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-23 13:18 . 2009-03-23 22:47 -------- d-----w- c:\documents and settings\S.A.H\Application Data\Save
2009-06-22 18:34 . 2008-12-28 08:53 -------- d-----w- c:\program files\Kaspersky Lab
2009-06-22 18:33 . 2009-01-14 21:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-22 11:35 . 2009-06-22 11:35 4096 ----a-w- c:\windows\system32\01.tmp
2009-06-21 00:46 . 2009-03-23 15:53 -------- d-----w- c:\program files\Ask Search Assistant
2009-06-19 17:26 . 2008-12-28 09:01 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-19 17:25 . 2009-01-05 18:34 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-19 17:23 . 2008-12-28 09:00 -------- d-----w- c:\program files\Common Files\InstallShield
2009-06-11 18:03 . 2008-12-31 23:48 -------- d-----w- c:\documents and settings\S.A.H\Application Data\SWF.max
2009-06-10 03:06 . 2008-12-29 14:41 127872 ----a-w- c:\documents and settings\الفوزان\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-09 22:42 . 2008-12-28 08:36 127872 ----a-w- c:\documents and settings\S.A.H\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-22 12:21 . 2009-01-12 09:39 -------- d-----w- c:\documents and settings\الفوزان\Application Data\SWF.max
2009-05-19 07:51 . 2008-12-28 08:55 196608 ----a-w- c:\windows\system32\maag.dll
2009-05-19 07:51 . 2008-12-28 08:55 1212416 ----a-w- c:\windows\system32\ckll.dll
2009-05-19 07:51 . 2008-12-28 08:55 2535424 ----a-w- c:\windows\system32\agsaamj.dll
2009-05-19 07:51 . 2008-12-28 08:55 1986560 ----a-w- c:\windows\system32\akll.dll
2009-05-19 07:51 . 2008-12-28 08:55 1245184 ----a-w- c:\windows\system32\bkll.dll
2009-05-19 07:51 . 2008-12-28 08:55 90112 ----a-w- c:\windows\system32\agsaami.dll
2009-05-19 07:51 . 2008-12-28 08:55 610304 ----a-w- c:\windows\system32\agsaamg.dll
2009-05-19 07:51 . 2008-12-28 08:55 372736 ----a-w- c:\windows\system32\agsaamc.dll
2009-05-19 07:51 . 2009-01-13 20:52 -------- d-----w- c:\program files\Real_SC
2009-05-10 09:36 . 2009-05-10 09:08 -------- d-----w- c:\program files\Karaoke5
2009-05-10 08:58 . 2009-05-10 08:50 -------- d-----w- c:\program files\TPlayer
2009-05-08 11:26 . 2009-05-08 11:26 -------- d-----w- c:\documents and settings\الفوزان\Application Data\Windows Live Writer
2004-08-03 21:55 . 2004-08-03 21:55 84320 --sha-r- c:\windows\system32\mcyggdqy.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-03 1667584]
"Save"="c:\documents and settings\S.A.H\Application Data\Save\Save.exe" [2009-03-23 198576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-28 185896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-5 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6760:TCP"= 6760:TCP:zxsbnb
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys --> c:\windows\system32\drivers\klbg.sys [?]
S2 ibmyq;Universal Server;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 12:56 ص 14336]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [22/06/2009 10:27 م 38496]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ibmyq
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-WhenUSave - c:\program files\Save\Save.exe
HKLM-Run-My Web Search Bar Search Scope Monitor - c:\progra~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearchMigratedDefaultURL = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZJman000&fl=0&ptb=iYNRI3tN1RFcf5aYUXHZzw&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
DPF: {7253A666-804A-1107-A4DC-00E04C504781} - hxxp://66.228.123.202/bmc.cab
DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} - hxxp://98.126.41.234:1999/ReadUid.CAB
DPF: {C171FF59-8C55-4796-A398-4F5D02B4C763} - hxxp://76.76.24.84/imscp/talks3n.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-23 16:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\TEMP\hpzcoi00.log 596 bytes
c:\windows\TEMP\hpzcoi01.log 596 bytes
c:\windows\TEMP\hpzcoi02.log 924 bytes
c:\windows\TEMP\hpzcoi03.log 678 bytes
c:\windows\TEMP\hpzcoi04.log 596 bytes
c:\windows\TEMP\hpzcoi05.log 596 bytes
c:\windows\TEMP\hpzcoi06.log 924 bytes
c:\windows\TEMP\hpzcoi07.log 678 bytes
c:\windows\TEMP\hpzcoi08.log 596 bytes
c:\windows\TEMP\hpzcoi09.log 596 bytes
c:\windows\TEMP\hpzcoi10.log 596 bytes
c:\windows\TEMP\hpzcoi11.log 596 bytes
c:\windows\TEMP\hpzcoi12.log 596 bytes
c:\windows\TEMP\hpzcoi13.log 596 bytes
c:\windows\TEMP\hpzcoi14.log 596 bytes
c:\windows\TEMP\hpzcoi15.log 596 bytes
c:\windows\TEMP\hpzglue00.log 328 bytes
c:\windows\TEMP\cch~7c4f47fa4.htp 8192 bytes
c:\windows\TEMP\cch~83831a052.htp 8192 bytes
c:\windows\TEMP\cch~838334e3b.htp 8192 bytes
c:\windows\TEMP\cch~752e06e1.htp 8192 bytes
c:\windows\TEMP\cch~752e117b.htp 8192 bytes
c:\windows\TEMP\cch~753c5fa4.htp 8192 bytes
c:\windows\TEMP\Perflib_Perfdata_bc8.dat 16384 bytes
c:\windows\TEMP\PR11B.tmp 65536 bytes
c:\windows\TEMP\SEP1.tmp 0 bytes
c:\windows\TEMP\SEP2.tmp 0 bytes
c:\windows\TEMP\SEP3.tmp 0 bytes
c:\windows\TEMP\servic000.log 102 bytes
c:\windows\TEMP\servic001.log 102 bytes
c:\windows\TEMP\Temporary Internet Files
c:\windows\TEMP\Temporary Internet Files\Content.IE5
c:\windows\TEMP\Temporary Internet Files\Content.IE5\3KMD83LA
c:\windows\TEMP\Temporary Internet Files\Content.IE5\3KMD83LA\alertspanel_en[1].gif 3493 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\3KMD83LA\desktop.ini 67 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\3KMD83LA\level_1[1].gif 101 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\3KMD83LA\menu_sep[1].gif 43 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\3KMD83LA\spacer[1].gif 49 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\3KMD83LA\submit_blue[1].gif 64 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\3KMD83LA\topMenuBgd_sand[1].gif 925 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\3KMD83LA\topthreats_en[1].gif 3560 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\3KMD83LA\virus_science[1].gif 76 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\CQC76781
c:\windows\TEMP\Temporary Internet Files\Content.IE5\CQC76781\desktop.ini 67 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\CQC76781\double_arrow[1].gif 53 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\CQC76781\index[1].htm 72470 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\CQC76781\level_2[1].gif 104 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\CQC76781\level_4[1].gif 86 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\CQC76781\rssfeeds_en[1].gif 2825 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\CQC76781\sand[1].jpg 285 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\CQC76781\search[1].gif 194 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\desktop.ini 67 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\G90CQ92I
c:\windows\TEMP\Temporary Internet Files\Content.IE5\G90CQ92I\buttonstats[1].gif 79 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\G90CQ92I\desktop.ini 67 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\G90CQ92I\front[1].css 10043 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\G90CQ92I\ico_print[1].gif 69 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\G90CQ92I\info[1].gif 190 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\G90CQ92I\logo_web[1].gif 3538 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\G90CQ92I\red_arrow_down[1].gif 80 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\G90CQ92I\removal_tool(1)[1].gif 5631 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\G90CQ92I\top_picture_en[1].jpg 23529 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\index.dat 49152 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\W1UNOPU7
c:\windows\TEMP\Temporary Internet Files\Content.IE5\W1UNOPU7\desktop.ini 67 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\W1UNOPU7\ga[1].js 22759 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\W1UNOPU7\latestthreats_en[1].gif 3993 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\W1UNOPU7\level_3[1].gif 106 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\W1UNOPU7\red_arrow[1].gif 81 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\W1UNOPU7\rss[1].gif 447 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\W1UNOPU7\v2_dot[1].gif 43 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\W1UNOPU7\v_dot[1].gif 43 bytes
c:\windows\TEMP\WGAErrLog.txt 461 bytes
c:\windows\TEMP\_ISTMP1.DIR
c:\windows\TEMP\_ISTMP1.DIR\_ISTMP0.DIR
c:\windows\TEMP\_ISTMP1.DIR\_ISTMP0.DIR\value.shl 728 bytes
c:\windows\TEMP\cch~694d5276.htp
c:\windows\TEMP\cch~839c90e8d.htp 8192 bytes
c:\windows\TEMP\cch~83a1d5a8c.htp 8192 bytes
c:\windows\TEMP\cch~c647a61f3.htp 8192 bytes
c:\windows\TEMP\cch~73b57506.htp 8192 bytes
c:\windows\TEMP\cch~73e9df79.htp 8192 bytes
c:\windows\TEMP\cch~86d6eac6.htp 8192 bytes
c:\windows\TEMP\cch~79b3fc53.htp 8192 bytes
c:\windows\TEMP\cch~834a12e60.htp 8192 bytes
c:\windows\TEMP\cch~9b32397f7.htp 8192 bytes
c:\windows\TEMP\cch~7493904e.htp 8192 bytes
c:\windows\TEMP\CIO_NDCS.log 589 bytes
c:\windows\TEMP\Cookies
c:\windows\TEMP\Cookies\index.dat 32768 bytes
c:\windows\TEMP\Cookies\s.a.h@avira[2].txt 356 bytes
c:\windows\TEMP\Cookies\s.a.h@www.avira[2].txt 72 bytes
c:\windows\TEMP\Cookies\الفوزان@avira[2].txt 356 bytes
c:\windows\TEMP\Cookies\الفوزان@www.avira[2].txt 73 bytes
c:\windows\TEMP\Google Toolbar
c:\windows\TEMP\Google Toolbar\gtm26.tmp 14500 bytes
c:\windows\TEMP\GoogleToolbarInstaller1.log 11208 bytes
c:\windows\TEMP\GoogleToolbarInstaller2.log 10102 bytes
c:\windows\TEMP\History
c:\windows\TEMP\History\History.IE5
c:\windows\TEMP\History\History.IE5\desktop.ini 113 bytes
c:\windows\TEMP\History\History.IE5\index.dat 32768 bytes
c:\windows\TEMP\HP000000.IDX 519781 bytes
c:\windows\TEMP\HP001000.IDX 61624 bytes
c:\windows\TEMP\HP002000.IDX 827197 bytes
c:\windows\TEMP\HP002001.PDL 813376 bytes
c:\windows\TEMP\hpdj00srv00.log 3005 bytes
c:\windows\TEMP\cch~b1e014ea4.htp 8192 bytes
c:\windows\TEMP\cch~b1e0169ad.htp 8192 bytes
c:\windows\TEMP\cch~b1e595bae.htp 8192 bytes
c:\windows\TEMP\cch~72bd7e9b.htp 8192 bytes
c:\windows\TEMP\cch~86d6f5b9.htp 8192 bytes
c:\windows\TEMP\cch~86e96e10.htp 8192 bytes
c:\windows\TEMP\cch~9b323bf2e.htp 8192 bytes
c:\windows\TEMP\cch~9dd7186d.htp 8192 bytes
c:\windows\TEMP\cch~9f83fee8c.htp 8192 bytes
c:\windows\TEMP\cch~a443d7dcd.htp 8192 bytes
c:\windows\TEMP\cch~af89f704d.htp 8192 bytes
c:\windows\TEMP\cch~b1e59cbf3.htp 8192 bytes
c:\windows\TEMP\cch~bea2e6ed2.htp 8192 bytes
c:\windows\TEMP\cch~c647a957a.htp 8192 bytes
c:\windows\TEMP\cch~cb87208f4.htp 8192 bytes
c:\windows\TEMP\cch~6ed3103c.htp 53550 bytes
c:\windows\TEMP\cch~6ed31895.htp
c:\windows\TEMP\cch~6ef163ca.htp
c:\windows\TEMP\cch~6ef45aed.htp
c:\windows\TEMP\cch~72bd6fa0.htp 8192 bytes
c:\windows\TEMP\cch~74d18279.htp 8192 bytes
c:\windows\TEMP\cch~74d1a0b3.htp 8192 bytes
c:\windows\TEMP\cch~748d03c4.htp 8192 bytes
c:\windows\TEMP\cch~83d32b239.htp 8192 bytes
c:\windows\TEMP\cch~cb7f39002.htp 8192 bytes
c:\windows\TEMP\cch~cb7f39ab6.htp 8192 bytes
c:\windows\TEMP\cch~cb861c9bd.htp 8192 bytes
c:\windows\TEMP\cch~cb8634adf.htp 8192 bytes
c:\windows\TEMP\cch~cb871fe99.htp 8192 bytes
c:\windows\TEMP\cch~bea2e6822.htp 8192 bytes
c:\windows\TEMP\cch~86e96328.htp 8192 bytes
c:\windows\TEMP\cch~d0dfaf27.htp 8192 bytes
c:\windows\TEMP\cch~d0dfb943.htp 8192 bytes
c:\windows\TEMP\cch~6a236cbf.htp
c:\windows\TEMP\cch~9f83fe4bf.htp 8192 bytes
c:\windows\TEMP\cch~63e9d609.htp
c:\windows\TEMP\cch~63e9dce6.htp 8192 bytes
c:\windows\TEMP\cch~63ec2e4d7.htp 8192 bytes
c:\windows\TEMP\cch~63ec2eee8.htp 8192 bytes
c:\windows\TEMP\cch~62b77ed3.htp 8192 bytes
c:\windows\TEMP\cch~a443d464f.htp 8192 bytes
c:\windows\TEMP\cch~9dd70ed5.htp 8192 bytes
c:\windows\TEMP\cch~65268398.htp
c:\windows\TEMP\cch~65268a73.htp
c:\windows\TEMP\cch~6529d9a9.htp
c:\windows\TEMP\cch~acbafdcfb.htp 0 bytes
c:\windows\TEMP\cch~af89f4fbc.htp 8192 bytes
c:\windows\TEMP\cch~61d5100f.htp
c:\windows\TEMP\cch~61d51747.htp
c:\windows\TEMP\cch~73b58032.htp 8192 bytes
c:\windows\TEMP\cch~73e9f57c.htp 8192 bytes
c:\windows\TEMP\cch~74914dc0.htp 8192 bytes
c:\windows\TEMP\cch~74949221.htp 8192 bytes
c:\windows\TEMP\cch~753c70fa.htp 8192 bytes
c:\windows\TEMP\cch~79b4072c.htp 8192 bytes
c:\windows\TEMP\cch~7c4f76909.htp 8192 bytes
c:\windows\TEMP\cch~834a1387a.htp 8192 bytes
c:\windows\TEMP\cch~839c904d9.htp 8192 bytes
c:\windows\TEMP\cch~83a1e0523.htp 8192 bytes
c:\windows\TEMP\cch~83d34c2ab.htp 8192 bytes
c:\windows\TEMP\cch~621182ddd.htp 8192 bytes
c:\windows\TEMP\cch~62b79185.htp 8192 bytes
c:\windows\TEMP\cch~652ac61d.htp
c:\windows\TEMP\cch~694d5973.htp
c:\windows\TEMP\cch~6a2373ef.htp
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ibmyq]
"ServiceDll"="c:\windows\system32\mcyggdqy.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):3e,4e,24,17,5f,c1,ae,ec,a0,b5,ae,2f,8a,e9,6d,d3,c9,52,b5,96,48,
1c,bc,4b,61,c3,4f,e2,a2,75,a6,0f,eb,90,e4,ae,79,7d,69,18,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{76be1795-f277-40b9-bb13-21639982a3fc}]
@Denied: (Full) (Everyone)
"Model"=dword:00000011
"Therad"=dword:00000007
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\combofix\hidec.exe
c:\program files\Windows Live\Toolbar\wltuser.exe
c:\combofix\Catchme.tmp
.
**************************************************************************
.
Completion time: 2009-06-23 16:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-23 13:22
Pre-Run: 25,436,323,840 bytes free
Post-Run: 28,687,073,280 bytes free
316