ComboFix 09-07-09.08 - a9z 07/12/2009 1:38.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.1979.1531 [GMT 3:00]
Running from: c:\documents and settings\a9z\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\2a.exe
C:\autorun.inf
c:\config\S-1-5-21-1482476501-1644491937-682003330-1013
c:\config\S-1-5-21-1482476501-1644491937-682003330-1013\ConfDriver.exe
c:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
c:\docume~1\a9z\LOCALS~1\Temp\00006C85_Rar\XP-BFC39513.EXE
c:\docume~1\a9z\LOCALS~1\Temp\E_4
c:\docume~1\a9z\LOCALS~1\Temp\E_4\com.run
c:\docume~1\a9z\LOCALS~1\Temp\E_4\dp1.fne
c:\docume~1\a9z\LOCALS~1\Temp\E_4\eAPI.fne
c:\docume~1\a9z\LOCALS~1\Temp\E_4\internet.fne
c:\docume~1\a9z\LOCALS~1\Temp\E_4\krnln.fnr
c:\docume~1\a9z\LOCALS~1\Temp\E_4\RegEx.fnr
c:\docume~1\a9z\LOCALS~1\Temp\E_4\shell.fne
c:\docume~1\a9z\LOCALS~1\Temp\E_4\spec.fne
c:\documents and settings\a9z\قائمة ابدأ\البرامج\بدء التشغيل\،،،،،،.lnk
c:\documents and settings\a9z\Local Settings\Temp\00006C85_Rar\XP-BFC39513.EXE
c:\documents and settings\a9z\Local Settings\Temp\E_4\com.run
c:\documents and settings\a9z\Local Settings\Temp\E_4\dp1.fne
c:\documents and settings\a9z\Local Settings\Temp\E_4\eAPI.fne
c:\documents and settings\a9z\Local Settings\Temp\E_4\internet.fne
c:\documents and settings\a9z\Local Settings\Temp\E_4\krnln.fnr
c:\documents and settings\a9z\Local Settings\Temp\E_4\RegEx.fnr
c:\documents and settings\a9z\Local Settings\Temp\E_4\shell.fne
c:\documents and settings\a9z\Local Settings\Temp\E_4\spec.fne
C:\fsaht.cmd
C:\gclwpivc.cmd
C:\icxpa.cmd
C:\lad.bat
c:\program files\AskSearch\bin\DefaultSearch.dll
C:\q9.cmd
C:\sm.exe
C:\ukvr.bat
C:\upx.bat
c:\windows\AhnRpta.exe
c:\windows\system32\com.run
c:\windows\system32\dp1.fne
c:\windows\system32\e8main0.dll
c:\windows\system32\e8main1.dll
c:\windows\system32\eAPI.fne
c:\windows\system32\internet.fne
c:\windows\system32\kakle.dll
c:\windows\system32\krnln.fnr
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\nmdfgds1.dll
c:\windows\system32\nmdfgds2.dll
c:\windows\system32\og.dll
c:\windows\system32\og.edt
c:\windows\system32\olhrwef.exe
c:\windows\system32\RegEx.fnr
c:\windows\system32\shell.fne
c:\windows\system32\spec.fne
c:\windows\system32\ul.dll
c:\windows\system32\XP-BFC39513.EXE
C:\xh319r9b.bat
C:\yhh.bat
D:\autorun.inf
D:\fsaht.cmd
D:\gclwpivc.cmd
D:\icxpa.cmd
D:\lad.bat
D:\q9.cmd
D:\ukvr.bat
D:\upx.bat
D:\xh319r9b.bat
D:\yhh.bat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
-------\Service_AVPsys
((((((((((((((((((((((((( Files Created from 2009-06-11 to 2009-07-11 )))))))))))))))))))))))))))))))
.
2009-07-10 21:41 . 2009-07-10 21:45 5944904 ----a-w- c:\documents and settings\a9z\Application Data\IDM\DwnlData\a9z\Zyzoom_kis2010_9.0.0.463AR_95\Zyzoom_kis2010_9.0.0.463AR.exe
2009-07-10 21:24 . 2009-07-10 21:34 16388655 ----a-w- c:\documents and settings\a9z\Application Data\IDM\DwnlData\a9z\Zyzoom_kis2010_9.0.0.463AR_92\Zyzoom_kis2010_9.0.0.463AR.exe
2009-07-09 14:30 . 2009-07-09 14:35 1030808 ----a-w- C:\installin.exe
2009-07-09 14:27 . 2004-12-26 00:23 652800 ----a-w- c:\documents and settings\a9z\Application Data\Microsoft\CryptnetUrlCache\MetaData\Internet Explorer\Data\iexplore\Explorer.pif
2009-07-08 07:23 . 2009-07-11 20:15 20480 ----a-w- c:\windows\system32\HV-78424.EXE
2009-07-08 07:23 . 2009-07-08 07:23 20480 --sh--w- c:\windows\system32\vt-7626.exe
2009-06-14 12:44 . 2009-07-10 21:46 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-14 12:44 . 2009-07-10 21:46 -------- d-----w- c:\program files\Common Files\PC Tools
2009-06-14 12:44 . 2009-07-10 21:46 -------- d-----w- c:\program files\Spyware Doctor
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-11 22:43 . 2009-05-12 18:36 2834 ----a-w- c:\documents and settings\a9z\Application Data\Microsoft\CryptnetUrlCache\MetaData\Internet Explorer\Data\iexplore\ms32.sys
2009-07-11 20:14 . 2001-09-19 12:00 40316 ----a-w- c:\windows\system32\perfc001.dat
2009-07-11 20:14 . 2001-09-19 12:00 251946 ----a-w- c:\windows\system32\perfh001.dat
2009-07-11 19:49 . 2009-05-08 19:09 -------- d-----w- c:\documents and settings\a9z\Application Data\uTorrent
2009-07-10 23:31 . 2009-05-09 18:39 -------- d-----w- c:\program files\Kaspersky Lab
2009-07-10 23:31 . 2009-05-04 05:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-10 22:37 . 2009-05-09 18:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-07-10 22:13 . 2009-05-02 05:16 -------- d-----w- c:\documents and settings\a9z\Application Data\IDM
2009-07-10 22:13 . 2009-05-02 05:15 -------- d-----w- c:\program files\Internet Download Manager
2009-07-10 22:11 . 2009-05-02 05:16 -------- d-----w- c:\documents and settings\a9z\Application Data\DMCache
2009-07-10 21:54 . 2009-06-11 21:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-07-08 22:29 . 2009-05-19 20:07 -------- d-----w- c:\documents and settings\a9z\Application Data\BSplayer
2009-07-08 06:53 . 2009-05-20 14:06 102400 ----a-w- c:\documents and settings\a9z\Application Data\IDM\DwnlData\a9z\Nero-6.6.1.15a_61\Nero-6.6.1.15a.exe
2009-07-06 20:06 . 2009-05-07 20:31 -------- d-----w- c:\documents and settings\a9z\Application Data\U3
2009-07-02 05:19 . 2009-05-18 11:14 -------- d-----w- c:\program files\Paltalk Messenger
2009-07-02 05:19 . 2009-05-18 11:14 -------- d-----w- c:\program files\ClocX
2009-06-11 21:28 . 2009-06-11 21:28 -------- d-----w- c:\program files\Avira
2009-06-11 10:48 . 2009-05-19 20:07 -------- d-----w- c:\program files\BS_Player
2009-06-03 14:47 . 2009-06-03 14:47 0 ----a-w- c:\windows\nsreg.dat
2009-06-02 23:06 . 2009-05-12 22:42 -------- d-----w- c:\program files\isoHunt
2009-06-01 21:34 . 2009-05-18 11:14 -------- d-----w- c:\documents and settings\a9z\Application Data\Paltalk
2009-05-28 11:34 . 2009-05-28 11:34 472584 ----a-w- c:\documents and settings\a9z\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-25 16:23 . 2009-05-01 09:10 92632 ----a-w- c:\documents and settings\a9z\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-25 13:00 . 2009-05-25 12:55 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-25 12:55 . 2009-05-01 09:04 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-22 11:20 . 2009-05-22 11:20 -------- d-----w- c:\program files\Microsoft.NET
2009-05-22 11:20 . 2009-05-22 11:20 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-05-20 18:40 . 2009-05-20 18:39 -------- d-----w- c:\program files\ALJAWAL 3.5G HSDPA DATA CARD
2009-05-20 14:26 . 2009-05-20 14:26 -------- d-----w- c:\documents and settings\a9z\Application Data\Nero
2009-05-20 14:14 . 2009-05-20 14:14 -------- d-----w- c:\program files\Common Files\Ahead
2009-05-20 14:14 . 2009-05-20 14:14 -------- d-----w- c:\program files\Nero
2009-05-19 20:07 . 2009-05-04 06:11 -------- d-----w- c:\documents and settings\a9z\Application Data\BSplayer PRO
2009-05-19 20:07 . 2009-05-04 06:11 -------- d-----w- c:\program files\Webteh
2009-05-18 21:54 . 2009-05-18 21:54 -------- d-----w- c:\documents and settings\a9z\Application Data\CyberLink
2009-05-18 11:32 . 2009-05-18 11:32 -------- d-----w- c:\documents and settings\a9z\Application Data\Media Player Classic
2009-05-18 11:31 . 2009-05-18 11:00 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-05-18 11:18 . 2009-05-18 11:18 -------- d-----w- c:\program files\MSECache
2009-05-18 11:10 . 2009-05-18 11:10 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-05-18 11:08 . 2009-05-18 11:08 -------- d-----w- c:\program files\Common Files\xing shared
2009-05-18 11:08 . 2009-05-02 23:05 -------- d-----w- c:\program files\Common Files\Real
2009-05-18 11:08 . 2009-05-18 11:08 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-05-18 11:08 . 2009-05-18 11:08 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-05-10 12:14 . 2009-05-10 12:14 1986560 ----a-w- c:\windows\system32\akll.dll
2009-05-10 12:14 . 2009-05-10 12:14 196608 ----a-w- c:\windows\system32\maag.dll
2009-05-10 12:14 . 2009-05-10 12:14 1245184 ----a-w- c:\windows\system32\bkll.dll
2009-05-10 12:14 . 2009-05-10 12:14 1212416 ----a-w- c:\windows\system32\ckll.dll
2009-05-10 12:14 . 2009-05-10 12:14 2535424 ----a-w- c:\windows\system32\agsaamj.dll
2009-05-10 12:14 . 2009-05-10 12:14 90112 ----a-w- c:\windows\system32\agsaami.dll
2009-05-10 12:14 . 2009-05-10 12:14 610304 ----a-w- c:\windows\system32\agsaamg.dll
2009-05-10 12:14 . 2009-05-10 12:14 372736 ----a-w- c:\windows\system32\agsaamc.dll
2009-05-07 15:42 . 2004-08-03 21:55 344064 ----a-w- c:\windows\system32\localspl.dll
2009-05-05 16:05 . 2009-05-03 19:02 172032 ------w- c:\windows\Setup1.exe
2009-05-05 16:05 . 2009-05-03 19:02 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-05-02 11:26 . 2009-05-01 08:51 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-02 06:30 . 2009-05-02 06:30 2232 ----a-w- c:\windows\java\Packages\Data\ZB5ZJ5N1.DAT
2009-05-02 06:30 . 2009-05-02 06:30 155995 ----a-w- c:\windows\java\Packages\FDBRDFHJ.ZIP
2009-05-02 06:30 . 2009-05-02 06:30 2678 ----a-w- c:\windows\java\Packages\Data\K9J9VRTR.DAT
2009-05-02 06:30 . 2009-05-02 06:30 2678 ----a-w- c:\windows\java\Packages\Data\OH35R5NR.DAT
2009-05-02 06:30 . 2009-05-02 06:30 2678 ----a-w- c:\windows\java\Packages\Data\V5FZR7JB.DAT
2009-05-02 06:30 . 2009-05-02 06:30 2678 ----a-w- c:\windows\java\Packages\Data\TVHFZRZH.DAT
2009-05-02 06:30 . 2009-05-02 06:30 2678 ----a-w- c:\windows\java\Packages\Data\NN7B3VZ9.DAT
2009-05-01 09:04 . 2009-05-01 09:04 319488 ----a-w- c:\windows\HideWin.exe
2009-05-01 08:48 . 2009-05-01 08:48 22144 ----a-w- c:\windows\system32\emptyregdb.dat
2009-04-29 04:51 . 2004-08-03 21:55 657920 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:51 . 2004-08-03 21:55 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-19 20:08 . 2004-08-03 21:46 1846528 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:12 . 2004-08-03 21:55 584192 ----a-w- c:\windows\system32\rpcrt4.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-18 09:58 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a6e4a4eb-d169-4e99-8988-250fcbafe767}]
2009-06-02 23:07 2094616 ----a-w- c:\program files\isoHunt\tbiso1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2009-06-11 10:48 2094616 ----a-w- c:\program files\BS_Player\tbBS_1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-02 39408]
"msnmsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5748080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-01 219672]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-01 272920]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-01 141848]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-02-07 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 136752]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-18 185896]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2004-04-13 181760]
"WinXPService"="c:\documents and settings\a9z\Application Data\Microsoft\CryptnetUrlCache\MetaData\Internet Explorer\Data\iexplore\Explorer.pif" [2004-12-26 652800]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-08-26 16851456]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-5-25 187392]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-12-20 576104]
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2009-4-25 11131392]
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= c:\\Program Files\\MSN Messenger\\MsnMsgr.Exe
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Documents and Settings\\a9z\\Application Data\\Microsoft\\CryptnetUrlCache\\MetaData\\Internet Explorer\\Data\\iexplore\\Explorer.pif"=
"c:\\Program Files\\ALJAWAL 3.5G HSDPA DATA CARD\\ALJAWAL 3.5G HSDPA DATA CARD.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"c:\\WINDOWS\\ALCMTR.EXE"=
"c:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe"=
"c:\\WINDOWS\\RTHDCPL.EXE"=
"c:\\Program Files\\ClocX\\ClocX.exe"=
"c:\\Program Files\\Mobily Connect Card\\Mobily Connect Card.exe"=
"c:\\Program Files\\MSN Messenger\\usnsvc.exe"=
"c:\\WINDOWS\\system32\\igfxpers.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\WINDOWS\\system32\\WgaTray.exe"=
"c:\\WINDOWS\\system32\\CF1777.exe"=
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [04/05/2009 04:47 م 110080]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [01/05/2009 12:17 م 156160]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [24/01/2009 08:12 ص 625024]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ASC3360PR
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{67EFG7H6-8IJL-56YT-KLH4-76WE2D3RAM87}]
c:\config\S-1-5-21-1482476501-1644491937-682003330-1013\ConfDriver.exe
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-XP-BFC39513 - c:\windows\system32\XP-BFC39513.EXE
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: أضافة إلى مانع الأعلانات - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
DPF: Microsoft XML Parser for Java -
DPF: {7253A666-804A-1107-A4DC-00E04C504781} - hxxp://66.228.123.202/bmc.cab
DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} - hxxp://98.126.41.66:1999/ReadUid.CAB
FF - ProfilePath - c:\documents and settings\a9z\Application Data\Mozilla\Firefox\Profiles\aev9dnw6.default\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-12 01:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{16cce327-2ff6-46a5-9c9e-e816f33fed3b}]
@Denied: (Full) (Everyone)
"Model"=dword:000000be
"Therad"=dword:00000001
"MData"=hex(0):cb,9b,ad,ef,27,7d,29,69,f5,02,f0,76,aa,4a,f1,7c,d3,d9,67,7f,6a,
4b,7b,ad,04,7a,b1,b5,76,9b,27,47,90,88,3e,08,b1,ce,42,20,13,b1,15,3c,46,79,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5351eb9a-6b70-45f2-929d-ce1ea2e0a8b4}]
@Denied: (Full) (Everyone)
"Model"=dword:00000096
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):f9,02,b4,86,6a,71,4a,f8,c5,d5,f2,d0,b5,e7,4a,9d,ab,ef,71,76,dc,
14,fd,68,dc,7b,32,6e,56,4c,dc,c7,27,b5,24,e7,9b,ba,89,01,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):ae,82,16,15,e6,98,39,6d,86,e1,fb,9b,86,36,3d,ba,55,09,3d,48,fd,
3e,cd,4d,a0,1c,dd,1a,4a,c8,eb,2b,94,75,3c,97,0e,4b,97,b2,00,00,00,00,00,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3876)
c:\windows\system32\browselc.dll
c:\windows\system32\msi.dll
c:\windows\system32\btmmhook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Mobily Connect Card\Mobily Connect Card.exe
c:\program files\MSN Messenger\usnsvc.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
.
**************************************************************************
.
Completion time: 2009-07-11 1:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-11 22:45
Pre-Run: 28,983,869,440 bytes free
Post-Run: 29,621,325,824 bytes free
317 --- E O F --- 2009-06-11 00:02