ComboFix 09-07-09.08 - adnan 07/11/2009 7:20.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.1014.580 [GMT 3:00]
Running from: c:\documents and settings\adnan\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\3j2h0tf.bat
c:\docume~1\adnan\LOCALS~1\Temp\nmdfgds0.dll
c:\documents and settings\adnan\Local Settings\Temp\nmdfgds0.dll
C:\p.exe
c:\program files\INSTALL.LOG
C:\uo10sn.cmd
c:\windows\AhnRpta.exe
c:\windows\system32\a
c:\windows\system32\e8main0.dll
c:\windows\system32\e8main1.dll
c:\windows\system32\kakle.dll
c:\windows\system32\mfc45.dll
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\nmdfgds2.dll
c:\windows\system32\olhrwef.exe
c:\windows\system32\winitn.dll
D:\3j2h0tf.bat
D:\uo10sn.cmd
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
((((((((((((((((((((((((( Files Created from 2009-06-11 to 2009-07-11 )))))))))))))))))))))))))))))))
.
2009-07-10 06:11 . 2009-07-10 06:14 -------- d-----w- c:\program files\Common Files\delet
2009-07-10 04:35 . 2009-07-10 04:35 -------- d-----w- c:\program files\Trend Micro
2009-07-09 06:34 . 2009-07-09 06:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-07-09 06:02 . 2009-07-09 06:26 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-07-09 05:15 . 2009-07-09 05:31 -------- d-----w- c:\windows\system32\NtmsData
2009-07-08 04:57 . 2009-07-08 04:57 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-07-08 04:09 . 2009-07-08 04:14 -------- d-----w- c:\program files\Error Repair Professional
2009-07-03 01:15 . 2009-07-03 01:15 106352 --sh--r- C:\cj1m.com
2009-07-01 17:46 . 2009-07-01 17:46 107917 --sh--r- C:\hifdmgt.com
2009-07-01 15:19 . 2009-07-01 15:19 -------- d-----w- c:\program files\tclock2_120
2009-07-01 15:18 . 2009-07-01 15:19 -------- d-----w- c:\program files\TrueTransparency
2009-07-01 15:18 . 2009-07-01 15:18 -------- d-----w- c:\program files\UberIcon
2009-07-01 15:18 . 2009-07-01 15:18 -------- d-----w- c:\program files\YzShadow
2009-07-01 15:13 . 2009-07-01 15:23 6998 ----a-w- c:\windows\BricoPackFoldersDelete.cmd
2009-06-30 17:58 . 2009-07-04 01:48 -------- d-----w- c:\program files\Mobily Connect Card
2009-06-29 13:46 . 2009-06-29 13:46 108386 --sh--r- C:\2nuk.com
2009-06-29 06:23 . 2009-06-29 06:23 106931 --sh--r- C:\n0euybx.exe
2009-06-27 14:02 . 2009-06-27 14:02 110278 --sh--r- C:\1mteolu9.com
2009-06-24 07:15 . 2009-06-24 07:15 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-06-22 07:05 . 2009-07-09 06:26 -------- d-----w- c:\program files\Freez_Online_TV
2009-06-22 06:37 . 2009-06-22 06:37 7680 ----a-w- c:\documents and settings\adnan\Application Data\Thinstall\Loaris Trojan Remover 1.1\4000008000002i\Splash Screen.exe
2009-06-17 05:00 . 2009-06-17 05:00 7680 ----a-w- c:\documents and settings\adnan\Application Data\Thinstall\Microsoft .NET Framework 2.0\4000003800002i\DiskCleanup.exe
2009-06-16 09:32 . 2009-06-16 09:32 -------- d-----w- c:\program files\JavaSoft
2009-06-16 09:32 . 2003-03-25 07:20 36968 ------w- c:\windows\system32\ActPanel.dll
2009-06-16 04:59 . 2009-06-17 05:04 -------- d-----w- C:\temp
2009-06-15 05:18 . 2009-06-15 05:18 -------- d-----w- c:\program files\MOTECH
2009-06-15 05:18 . 2006-08-07 12:22 276620 ----a-w- c:\windows\system32\drivers\BTCap.sys
2009-06-15 05:18 . 2006-04-19 22:22 102400 ----a-w- c:\windows\system32\DSCMJPG.dll
2009-06-12 05:04 . 2009-02-09 11:41 2064512 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-06-12 05:04 . 2009-02-09 11:41 2022400 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-06-12 05:04 . 2009-02-09 11:41 2187648 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-06-12 05:03 . 2009-02-09 11:41 2144256 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-06-12 04:28 . 2008-06-14 17:59 271616 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-06-12 04:28 . 2008-06-14 17:59 271616 ------w- c:\windows\system32\drivers\bthport.sys
2009-06-12 04:10 . 2008-10-24 11:25 455936 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-10 14:51 . 2009-05-07 14:27 -------- d-----w- c:\program files\MacSearch_v.1.4.3
2009-07-10 06:59 . 2009-04-26 10:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Long slow road itch
2009-07-10 06:02 . 2009-07-10 05:29 -------- d-----w- c:\documents and settings\adnan\Application Data\cleaner
2009-07-10 05:29 . 2009-07-10 05:29 -------- d-----w- c:\documents and settings\adnan\Application Data\CyberScrub
2009-07-09 06:24 . 2009-06-08 11:54 -------- d-----w- c:\program files\CoffeeCup Software
2009-07-09 06:02 . 2009-05-20 00:24 -------- d-----w- c:\program files\************
2009-07-08 04:57 . 2009-04-26 01:24 -------- d-----w- c:\program files\Windows Live
2009-07-08 03:37 . 2009-05-11 21:37 -------- d-----w- c:\documents and settings\adnan\Application Data\QuickScan
2009-07-06 20:36 . 2009-05-26 15:37 656960 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-07-04 01:49 . 2009-06-10 01:40 -------- d-----w- c:\program files\iolo
2009-07-04 01:47 . 2009-04-26 12:32 -------- d-----w- c:\program files\Panda Security
2009-07-04 01:42 . 2009-04-26 10:25 -------- d-----w- c:\program files\Pwndsoft
2009-07-01 15:37 . 2009-04-26 10:17 -------- d-----w- c:\program files\PremierOpinion
2009-07-01 15:23 . 2009-05-07 14:29 154883 ----a-w- c:\windows\BricoPackUninst.cmd
2009-07-01 15:19 . 2009-05-07 14:27 -------- d-----w- c:\program files\CursorXP
2009-06-30 16:37 . 2009-06-01 01:19 -------- d-----w- c:\documents and settings\adnan\Application Data\Desktopicon
2009-06-22 06:37 . 2009-04-30 21:34 -------- d-----w- c:\documents and settings\adnan\Application Data\Thinstall
2009-06-22 04:55 . 2001-09-19 12:00 68842 ----a-w- c:\windows\system32\perfc001.dat
2009-06-22 04:55 . 2001-09-19 12:00 370218 ----a-w- c:\windows\system32\perfh001.dat
2009-06-18 06:00 . 2009-05-04 04:02 -------- d-----w- c:\documents and settings\adnan\Application Data\DMCache
2009-06-16 09:32 . 2009-04-25 11:48 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-10 09:48 . 2009-06-10 09:48 1519 ----a-w- c:\documents and settings\adnan\Application Data\iolo\restore.bat
2009-06-10 09:48 . 2009-06-10 01:37 -------- d-----w- c:\documents and settings\adnan\Application Data\iolo
2009-06-10 09:35 . 2009-05-02 00:36 -------- d-----w- c:\program files\ARAR
2009-06-10 01:43 . 2009-06-10 01:37 -------- d-----w- c:\documents and settings\All Users\Application Data\iolo
2009-06-10 01:40 . 2009-06-10 01:40 -------- d-----w- c:\documents and settings\LocalService\Application Data\iolo
2009-06-09 12:38 . 2009-06-09 12:38 -------- d-----w- c:\documents and settings\adnan\Application Data\EPSON
2009-06-09 11:49 . 2009-04-25 11:48 -------- d-----w- c:\program files\Common Files\InstallShield
2009-06-09 11:40 . 2009-06-09 11:40 -------- d-----w- c:\documents and settings\All Users\Application Data\UDL
2009-06-09 11:39 . 2009-06-09 11:29 -------- d-----w- c:\program files\epson
2009-06-09 11:33 . 2009-06-09 11:33 -------- d-----w- c:\documents and settings\adnan\Application Data\InstallShield
2009-06-09 11:33 . 2009-06-09 11:33 -------- d-----w- c:\documents and settings\All Users\Application Data\EPSON
2009-06-09 11:26 . 2009-04-29 04:11 -------- d-----w- c:\program files\Google
2009-06-09 00:34 . 2009-06-08 12:00 -------- d-----w- c:\program files\ICQLite
2009-06-09 00:28 . 2009-06-08 11:58 -------- d-----w- c:\program files\Microsoft Chat
2009-06-08 12:08 . 2009-06-08 12:08 -------- d-----w- c:\program files\GIF Movie Gear
2009-06-08 12:08 . 2009-06-08 12:08 286720 ----a-w- c:\windows\iun506.exe
2009-06-08 12:03 . 2009-05-09 20:35 -------- d-----w- c:\program files\GTRipple
2009-06-08 11:56 . 2009-06-08 11:56 -------- d-----w- c:\program files\Voicemask
2009-06-05 01:20 . 2009-05-01 03:29 -------- d-----w- c:\documents and settings\adnan\Application Data\Nokia
2009-06-03 06:14 . 2009-06-03 06:14 -------- d-----w- c:\documents and settings\adnan\Application Data\Media Player Classic
2009-06-03 06:13 . 2009-06-03 06:13 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-06-02 11:00 . 2009-04-25 23:46 10697 ----a-w- c:\documents and settings\All Users\Application Data\DVD X Studios\DVD X Player 4.1 Professional\DVDXPlayer.dll
2009-06-01 16:44 . 2009-06-01 16:29 21878064 ----a-w- c:\documents and settings\adnan\Application Data\Sony Setup\A189E68E-2253-4C3B-86B7-D77E36F13C55\QuickTimeInstaller.exe
2009-06-01 16:29 . 2009-06-01 16:29 -------- d-----w- c:\documents and settings\adnan\Application Data\Sony Setup
2009-06-01 16:28 . 2009-06-01 16:28 -------- d-----w- c:\program files\Sony Setup
2009-06-01 01:10 . 2009-06-01 01:09 -------- d-----w- c:\program files\FormatFactory
2009-05-30 23:21 . 2009-05-30 23:21 -------- d-----w- c:\documents and settings\adnan\Application Data\GeoVid
2009-05-30 23:19 . 2009-05-30 23:19 -------- d-----w- c:\program files\Common Files\GeoVid
2009-05-30 23:19 . 2009-05-30 23:19 -------- d-----w- c:\documents and settings\All Users\Application Data\GeoVid
2009-05-30 23:19 . 2009-05-30 23:19 -------- d-----w- c:\program files\GeoVid
2009-05-28 17:25 . 2009-05-27 12:35 -------- d-----w- c:\documents and settings\adnan\Application Data\PC Suite
2009-05-28 05:30 . 2009-05-27 21:46 -------- d-----w- c:\documents and settings\adnan\Application Data\Nseries
2009-05-28 02:33 . 2009-04-30 03:21 -------- d-----w- c:\program files\JetAudio
2009-05-27 17:54 . 2009-05-27 12:35 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-05-27 12:33 . 2009-04-25 23:49 -------- d-----w- c:\program files\Nokia
2009-05-27 12:28 . 2009-05-01 03:28 -------- d-----w- c:\program files\Common Files\Nokia
2009-05-27 12:24 . 2009-05-27 12:24 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9F59C3AE-81B0-4EF6-9762-D674BB079705}\Installer\CommonCustomActions\msxml6Exec.exe
2009-05-27 12:24 . 2009-05-27 12:24 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9F59C3AE-81B0-4EF6-9762-D674BB079705}\Installer\CommonCustomActions\Sleep.exe
2009-05-27 12:24 . 2009-05-27 12:24 3181612 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9F59C3AE-81B0-4EF6-9762-D674BB079705}\Installer\CommonCustomActions\vcredistExec.exe
2009-05-27 12:24 . 2009-05-26 17:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-05-27 12:24 . 2009-05-27 12:25 24433136 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9F59C3AE-81B0-4EF6-9762-D674BB079705}\NokiaSoftwareUpdaterSetup_1.6.13AR.exe
2009-05-27 12:03 . 2009-05-27 12:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2009-05-27 05:27 . 2009-05-27 05:27 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-05-27 05:27 . 2009-05-27 05:27 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-05-26 22:31 . 2009-04-26 00:11 104776 ----a-w- c:\documents and settings\adnan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-26 17:36 . 2009-05-26 17:36 -------- d-----w- c:\program files\MSXML 6.0
2009-05-26 17:32 . 2009-05-26 17:31 -------- d-----w- c:\program files\Common Files\muvee Technologies
2009-05-26 15:35 . 2009-04-29 02:09 -------- d-----w- c:\program files\MSBuild
2009-05-26 15:34 . 2009-05-26 15:34 -------- d-----w- c:\program files\Reference Assemblies
2009-05-26 03:41 . 2009-05-26 03:41 -------- d-----w- c:\documents and settings\All Users\Application Data\TVU Networks
2009-05-26 03:28 . 2009-04-26 00:06 -------- d-----w- c:\program files\Picasa2
2009-05-26 01:29 . 2009-04-29 02:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-20 05:20 . 2009-05-20 05:20 7680 ----a-w- c:\documents and settings\adnan\Application Data\Thinstall\Microsoft .NET Framework 2.0\4000003000002i\RecoveryCenter.exe
2009-05-20 05:19 . 2009-05-20 05:19 7680 ----a-w- c:\documents and settings\adnan\Application Data\Thinstall\Microsoft .NET Framework 2.0\4000002a00002i\StartupMgr.exe
2009-05-20 05:12 . 2009-05-20 05:12 7680 ----a-w- c:\documents and settings\adnan\Application Data\Thinstall\Microsoft .NET Framework 2.0\4000009a00002i\RegistryDefrag.exe
2009-05-20 05:05 . 2009-05-20 05:05 7680 ----a-w- c:\documents and settings\adnan\Application Data\Thinstall\Microsoft .NET Framework 2.0\4000005a00002i\RegistryRepair.exe
2009-05-20 05:04 . 2009-05-20 05:04 7680 ----a-w- c:\documents and settings\adnan\Application Data\Thinstall\Microsoft .NET Framework 2.0\4000001100002i\mscorsvw.exe
2009-05-20 00:42 . 2009-05-20 00:42 -------- d-----w- c:\documents and settings\adnan\Application Data\AltrixSoft
2009-05-20 00:24 . 2009-05-20 00:24 -------- d-----w- c:\program files\Conduit
2009-05-19 13:14 . 2009-05-19 13:14 -------- d-----w- c:\program files\hp LaserJet 1000
2009-05-13 08:49 . 2009-05-13 08:49 -------- d-----w- c:\program files\Alwil Software
2009-05-12 09:09 . 2009-05-12 08:51 -------- d-----w- c:\documents and settings\adnan\Application Data\Windows Live Writer
2009-05-12 04:20 . 2009-05-12 04:21 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-11 21:55 . 2009-05-11 21:55 152576 ----a-w- c:\documents and settings\adnan\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-07 15:42 . 2004-08-03 22:55 344064 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 14:29 . 2009-07-01 15:23 218624 ----a-w- c:\windows\system32\nsg645.tmp
2009-05-07 14:29 . 2004-08-03 22:55 218624 ----a-w- c:\windows\system32\uxtheme.dll
2009-05-02 09:47 . 2009-05-02 09:47 48 ----a-w- c:\windows\system32\TTGMEval.Dat
2009-05-01 18:30 . 2009-05-01 18:30 3366912 ----a-w- c:\windows\system32\GPhotos.scr
2009-04-30 03:17 . 2009-04-30 03:17 47360 ----a-w- c:\windows\system32\drivers\Pcouffin.sys
2009-04-30 00:52 . 2005-05-31 22:36 44944 ------w- c:\windows\system32\drivers\pxhelp20.sys
2009-04-30 00:52 . 2009-04-30 00:52 158192 ------w- c:\windows\system32\pxwma.dll
2009-04-29 04:30 . 2009-07-01 15:16 6462464 ----a-w- c:\windows\system32\nsf142.tmp
2009-04-29 04:30 . 2009-07-01 15:16 6448640 ----a-w- c:\windows\system32\nsb140.tmp
2009-04-29 04:30 . 2009-07-01 15:15 1473536 ----a-w- c:\windows\system32\nscF2.tmp
2009-04-29 04:30 . 2009-07-01 15:16 2399744 ----a-w- c:\windows\system32\nse190.tmp
2009-04-29 04:30 . 2009-07-01 15:16 635392 ----a-w- c:\windows\system32\nsz172.tmp
2009-04-29 04:30 . 2007-04-23 04:53 666624 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:30 . 2009-07-01 15:16 5076992 ----a-w- c:\windows\system32\nsv16E.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-02 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-09 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-06-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-06-13 118784]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-07-19 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-29 766041]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2007-05-14 35328]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Glass2k"="c:\windows\BricoPacks\LeopardXP\Glass2k.exe" [2008-05-22 56325]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-07-19 16248320]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-07-19 2879488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [2007-04-23 12451]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-03 44544]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2004-08-03 99840]
c:\documents and settings\adnan\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Glass2k.lnk - c:\windows\BricoPacks\LeopardXP\Glass2k.exe [2008-5-22 56325]
MacSearch.lnk - c:\program files\MacSearch_v.1.4.3\MacSearch.exe [2006-2-19 201911]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
panther.CurXPTheme.lnk - c:\program files\CursorXP\Themes\panther.CurXPTheme [2009-5-7 29383]
RK Launcher.lnk - c:\program files\RK Launcher\RK Launcher 0.41 Beta Nightly\RKLauncher.exe [2007-3-16 708608]
tclock2.lnk - c:\program files\tclock2_120\tclock2.exe [2003-8-3 90624]
TrueTransparency.lnk - c:\program files\TrueTransparency\TrueTransparency.exe [2008-5-27 371200]
UberIcon.lnk - c:\program files\UberIcon\UberIcon Manager.exe [2005-8-12 180224]
YzShadow.lnk - c:\program files\YzShadow\YzShadow.exe [2002-9-30 151552]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-1-17 618557]
Nokia Ovi Suite.lnk - c:\program files\Nokia\Ovi\Suite\RunLauncher.exe [2008-7-25 951600]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"googletalk"=c:\program files\Google\Google Talk\googletalk.exe /autostart
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Nokia\\Nokia Home Media Server\\Media Server\\twonkymedia.exe"=
"c:\\Program Files\\Nokia\\Nokia Home Media Server\\Media Server\\twonkymediaserver.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\program files\\premieropinion\\pmropn.exe"=
R2 BTCAP;Bluetooth, WDM Video Capture;c:\windows\system32\drivers\BTCap.sys [15/06/2009 08:18 ص 276620]
R3 lv321av;Logitech USB PC Camera (VC0321);c:\windows\system32\drivers\lv321av.sys [25/04/2009 03:12 م 1097728]
S2 TwonkyMedia;TwonkyMedia;c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 --> c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 [?]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [27/05/2009 03:33 م 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [27/05/2009 03:33 م 8320]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA844-CC51-11CF-AAFA-00AA00B6015C}]
rundll32.exe advpack.dll,LaunchINFSection c:\windows\INF\CChat25.inf,PerUserAdd.NT
.
Contents of the 'Scheduled Tasks' folder
2009-07-10 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:53]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
TCP: {20148B70-7ABE-412C-A829-D154F3C44049} = 192.168.1.70
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
txtfile=NOTEPAD %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
vbefile\shell\edit\command=%SystemRoot%\System32\Notepad.exe %1
vbsfile\shell\edit\command=c:\windows\Notepad.exe %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-11 07:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-854245398-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D13ACE2B-D749-5045-F153-0ED1B2882FC7}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1116)
c:\program files\RK Launcher\RK Launcher 0.41 Beta Nightly\RKLauncher.dll
c:\program files\YzShadow\YzShadow.dll
c:\program files\TrueTransparency\TrueTransparencyHook.dll
c:\program files\UberIcon\UberIcon.dll
c:\windows\system32\msi.dll
c:\program files\tclock2_120\tc2dll.tclock
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\CursorXP\CursorXP.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\docume~1\adnan\LOCALS~1\Temp\RtkBtMnt.exe
.
**************************************************************************
.
Completion time: 2009-07-11 7:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-11 04:43
Pre-Run: 28,064,137,216 bytes free
Post-Run: 28,236,095,488 bytes free
315 --- E O F --- 2009-06-12 09:10
تفضل اخي maax