ComboFix 09-07-14.08 - ماجد 07/16/2009 18:30.1.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.503.249 [GMT 3:00]
Running from: c:\documents and settings\ماجد\سطح المكتب\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-06-16 to 2009-07-16 )))))))))))))))))))))))))))))))
.
2009-07-16 14:31 . 2009-07-16 14:31 -------- d-----w- c:\program files\Trend Micro
2009-07-11 21:35 . 2009-07-11 21:35 -------- d-sh--w- C:\FOUND.015
2009-07-07 22:39 . 2009-07-07 22:39 -------- d-----w- c:\program files\Common Files\PCSuite
2009-07-07 22:39 . 2009-07-07 22:39 -------- d-----w- c:\program files\Common Files\Nokia
2009-07-07 22:38 . 2009-07-07 22:38 -------- d-----w- c:\program files\PC Connectivity Solution
2009-07-07 22:37 . 2009-02-09 05:37 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2009-07-07 22:37 . 2009-02-09 05:37 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll
2009-07-07 22:37 . 2009-02-09 05:37 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2009-07-07 22:37 . 2009-02-09 05:32 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2009-07-07 22:36 . 2009-07-07 22:33 34008688 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_ara.exe
2009-07-07 22:36 . 2009-07-07 22:36 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-07-07 22:36 . 2009-07-07 22:36 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-07-07 22:36 . 2009-07-07 22:36 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-07-07 22:36 . 2009-07-07 22:36 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-07-05 21:45 . 2009-07-05 21:45 -------- d-sh--w- C:\FOUND.014
2009-07-02 19:15 . 2009-07-02 19:15 -------- d-sh--w- C:\FOUND.013
2009-07-02 19:13 . 2009-07-02 19:13 -------- d-sh--w- C:\FOUND.012
2009-06-26 23:14 . 2009-06-26 23:14 -------- d-----w- c:\documents and settings\ماجد\Application Data\FLVPlayer4Free
2009-06-26 23:14 . 2009-06-26 23:14 -------- d-----w- c:\program files\FLVPlayer4Free
2009-06-26 14:42 . 2009-06-26 14:42 -------- d-----w- c:\program files\Online TV Player
2009-06-26 14:41 . 2009-06-26 14:41 -------- d-----w- c:\documents and settings\ماجد\Application Data\GetRightToGo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-01-02 10:43 . 2009-03-05 15:20 77176 ----a-w- c:\windows\Fonts\SC_OUHOD.ttf
2016-12-30 05:32 . 2009-03-05 15:20 90072 ----a-w- c:\windows\Fonts\SC_REHAN.ttf
2016-12-30 05:06 . 2009-03-05 15:20 70064 ----a-w- c:\windows\Fonts\SC_TARABLUS.ttf
2016-12-30 05:05 . 2009-03-05 15:20 102264 ----a-w- c:\windows\Fonts\SC_SHMOOKH01.ttf
2016-12-30 05:05 . 2009-03-05 15:20 66792 ----a-w- c:\windows\Fonts\SC_SHARJAH.ttf
2016-12-30 05:04 . 2009-03-05 15:20 66852 ----a-w- c:\windows\Fonts\SC_LUJAYN.ttf
2016-12-30 05:03 . 2009-03-05 15:20 64908 ----a-w- c:\windows\Fonts\SC_KHALID.ttf
2016-12-30 05:03 . 2009-03-05 15:20 63168 ----a-w- c:\windows\Fonts\SC_HANI.ttf
2016-12-30 05:02 . 2009-03-05 15:20 81648 ----a-w- c:\windows\Fonts\SC_GULF.ttf
2016-12-30 05:02 . 2009-03-05 15:20 75820 ----a-w- c:\windows\Fonts\SC_DUBAI.ttf
2016-12-30 05:01 . 2009-03-05 15:20 70368 ----a-w- c:\windows\Fonts\SC_AMEEN.ttf
2016-12-30 05:00 . 2009-03-05 15:20 86304 ----a-w- c:\windows\Fonts\SC_ALYERMOOK.ttf
2009-07-16 12:10 . 2001-09-19 09:00 40962 ----a-w- c:\windows\system32\perfc001.dat
2009-07-16 12:10 . 2001-09-19 09:00 254578 ----a-w- c:\windows\system32\perfh001.dat
2009-06-16 14:53 . 2004-08-03 18:55 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:53 . 2001-09-19 09:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-07 14:22 . 2009-06-07 14:22 -------- d-----w- c:\program files\Muslim Bag
2009-06-04 16:06 . 2009-06-04 16:06 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-06-04 16:06 . 2009-06-04 16:06 -------- d-----w- c:\documents and settings\ماجد\Application Data\skypePM
2009-06-04 15:57 . 2009-06-04 15:57 -------- d-----w- c:\documents and settings\ماجد\Application Data\Skype
2009-06-04 15:57 . 2009-06-04 15:57 -------- d-----w- c:\program files\Common Files\Skype
2009-06-04 15:57 . 2009-06-04 15:57 -------- d-----r- c:\program files\Skype
2009-06-04 15:56 . 2009-06-04 15:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-06-04 15:26 . 2009-06-04 15:26 -------- d-----w- c:\documents and settings\ماجد\Application Data\TeamViewer
2009-06-03 19:25 . 2004-08-03 18:55 1288704 ----a-w- c:\windows\system32\quartz.dll
2009-05-27 21:54 . 2009-05-27 21:54 390664 ----a-w- c:\documents and settings\ماجد\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-07 15:42 . 2004-08-03 18:55 344064 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 14:36 . 2009-05-07 14:36 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-05-07 14:36 . 2009-05-07 14:36 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-05-07 14:36 . 2009-05-07 14:36 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-05-07 14:35 . 2009-05-07 14:36 34649904 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_ara.exe
2009-04-29 04:51 . 2004-08-03 18:55 657920 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:51 . 2004-08-03 18:55 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-19 20:08 . 2004-08-03 18:46 1846528 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-23 39408]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-01-22 2577840]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-05-26 24264488]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-22 185896]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-10-25 1410304]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2005-12-09 15691264]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-4-19 64864]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [25/10/2007 09:26 ص 455936]
S2 gupdate1c9e52d3e02eb3c;خدمة تحديث Google (gupdate1c9e52d3e02eb3c);c:\program files\Google\Update\GoogleUpdate.exe [04/06/2009 06:57 م 133104]
.
Contents of the 'Scheduled Tasks' folder
2009-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-04 15:57]
2009-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-04 15:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-16 18:33
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):6f,39,a4,d1,e5,eb,dc,a3,56,90,cd,3c,07,2b,8e,f0,a0,35,78,94,29,
e0,ca,2b,ba,b4,6c,86,07,fd,ec,39,13,de,f4,6e,38,91,47,29,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{fefdcdb3-c796-44a6-97b0-ec6218aeb717}]
@Denied: (Full) (Everyone)
"Model"=dword:000000b1
"Therad"=dword:0000001e
"MData"=hex(0):cb,9b,ad,ef,27,7d,29,69,f5,02,f0,76,aa,4a,f1,7c,d3,d9,67,7f,6a,
4b,7b,ad,04,7a,b1,b5,76,9b,27,47,9c,2b,74,9c,4b,39,92,e2,95,a4,d8,af,7c,59,\
.
Completion time: 2009-07-16 18:34
ComboFix-quarantined-files.txt 2009-07-16 15:34
Pre-Run: 10,182,623,232 bytes free
Post-Run: 10,335,977,472 bytes free
169 --- E O F --- 2009-07-15 23:57