ComboFix 09-07-28.04 - mohammad 07/29/2009 13:38.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.974.1033.18.255.129 [GMT 3:00]
Running from: c:\documents and settings\mohammad\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\cv8j.exe
c:\docume~1\mohammad\LOCALS~1\Temp\E_4
c:\docume~1\mohammad\LOCALS~1\Temp\E_4\eAPI.fne
c:\docume~1\mohammad\LOCALS~1\Temp\E_4\krnln.fnr
c:\docume~1\mohammad\LOCALS~1\Temp\E_4\RegEx.fnr
c:\docume~1\mohammad\LOCALS~1\Temp\E_4\spec.fne
c:\windows\AhnRpta.exe
c:\windows\artools.dll
c:\windows\Installer\28730f.msp
c:\windows\Installer\28732c.msp
c:\windows\Installer\287341.msp
c:\windows\Installer\287356.msp
c:\windows\Installer\28736c.msp
c:\windows\Installer\287382.msp
c:\windows\Installer\287397.msp
c:\windows\Installer\2873ad.msp
c:\windows\Installer\2873c2.msp
c:\windows\Installer\2873df.msp
c:\windows\Installer\2873f5.msp
c:\windows\Installer\28740e.msp
c:\windows\Installer\287424.msp
c:\windows\Installer\28743a.msp
c:\windows\Installer\287454.msp
c:\windows\Installer\395936.msi
c:\windows\Installer\429f5d.msp
c:\windows\Installer\a08235.msi
c:\windows\Installer\a326b9.msi
c:\windows\system32\com.run
c:\windows\system32\dp1.fne
c:\windows\system32\e8main1.dll
c:\windows\system32\eAPI.fne
c:\windows\system32\internet.fne
c:\windows\system32\kakle.dll
c:\windows\system32\krnln.fnr
c:\windows\system32\og.dll
c:\windows\system32\og.edt
c:\windows\system32\RegEx.fnr
c:\windows\system32\setting.ini
c:\windows\system32\shell.fne
c:\windows\system32\spec.fne
c:\windows\system32\ul.dll
c:\windows\system32\winio.vxd
c:\windows\system32\winitn.dll
C:\xs6kpr0.exe
D:\autorun.inf
D:\cv8j.exe
D:\xs6kpr0.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-29 )))))))))))))))))))))))))))))))
.
2009-07-28 16:40 . 2009-07-28 16:45 108489 --sh--r- C:\mb9x.exe
2009-07-28 16:26 . 2009-07-28 16:26 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-07-28 16:23 . 2009-07-28 16:23 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-07-28 16:23 . 2009-07-28 16:23 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-07-28 16:21 . 2009-07-29 08:51 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2009-07-28 16:21 . 2009-07-28 16:21 -------- d-----w- c:\program files\Kaspersky Lab
2009-07-28 13:01 . 2009-07-28 13:01 3584 ----a-r- c:\documents and settings\mohammad\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2009-07-28 13:01 . 2009-07-28 13:01 -------- d-----w- c:\program files\Windows Installer Clean Up
2009-07-28 12:36 . 2009-07-28 12:36 250 ----a-w- C:\Repair.reg
2009-07-28 11:56 . 2009-07-28 11:56 -------- d-----w- c:\documents and settings\mohammad\Application Data\URSoft
2009-07-28 11:53 . 2009-07-28 11:59 -------- d-----w- c:\program files\VS Revo Group
2009-07-28 11:15 . 2009-07-27 08:57 108548 --sh--r- C:\u0riu2.exe
2009-07-28 11:08 . 2009-07-28 11:08 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2009-07-27 21:44 . 2009-07-27 21:44 -------- d-----w- c:\program files\MSXML 4.0
2009-07-27 18:28 . 2009-07-27 18:35 -------- d-----w- c:\program files\Common Files\delet
2009-07-27 17:22 . 2009-07-27 18:50 4595744 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-27 11:33 . 2009-07-27 11:33 -------- d-----w- c:\program files\Trend Micro
2009-07-27 11:23 . 2009-07-27 11:23 -------- d-----w- c:\documents and settings\mohammad\Local Settings\Application Data\Runscanner.net
2009-07-26 08:43 . 2009-07-27 06:07 108204 --sh--r- C:\hm1bfpuj.exe
2009-07-18 19:09 . 2009-07-18 19:14 -------- d-----w- c:\documents and settings\mohammad\Application Data\Gold Wave Editor Pro
2009-07-18 14:40 . 2003-08-15 21:55 348160 ----a-w- c:\windows\system32\eSellerateEngine.dll
2009-07-17 04:25 . 2009-07-17 04:25 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2009-07-15 22:47 . 2009-07-15 22:47 -------- d-----w- c:\documents and settings\mohammad\Local Settings\Application Data\ESET
2009-07-15 22:45 . 2009-07-15 22:45 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\ESET
2009-07-13 20:39 . 2009-07-14 03:41 -------- d-----w- c:\windows\system32\Sys52Data
2009-07-13 20:39 . 2009-07-21 18:14 -------- d-----w- c:\program files\A8GSdsApp
2009-07-13 16:50 . 2009-07-13 16:52 -------- d-----w- c:\program files\Common Files\HP
2009-07-13 16:49 . 2009-07-13 16:49 -------- d-----w- c:\program files\Hewlett-Packard
2009-07-13 16:45 . 2009-07-13 17:01 144594 ----a-w- c:\windows\hpoins12.dat
2009-07-13 16:45 . 2007-01-22 16:05 1470 ------w- c:\windows\hpomdl12.dat
2009-07-09 15:52 . 2009-07-09 15:52 59976 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2010 9.0.0.463\English\setup.exe
2009-07-07 15:30 . 2009-07-27 12:20 -------- d-----w- c:\program files\Real_SC
2009-07-07 13:33 . 2009-07-07 13:33 -------- d-----w- c:\documents and settings\mohammad\Application Data\Printer Info Cache
2009-07-07 13:33 . 2009-07-13 17:53 -------- d-----w- c:\documents and settings\mohammad\Application Data\Image Zone Express
2009-07-07 13:33 . 2009-07-07 13:33 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\WEBREG
2009-07-07 13:32 . 2009-07-07 13:32 -------- d-----w- c:\documents and settings\mohammad\Application Data\HP
2009-07-07 13:29 . 2009-07-07 12:04 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\HP
2009-07-07 13:27 . 2009-07-07 13:27 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-07-07 13:26 . 2006-12-06 06:02 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2009-07-07 13:26 . 2006-12-06 06:02 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2009-07-07 13:25 . 2009-07-07 13:25 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Hewlett-Packard
2009-07-07 13:25 . 2006-12-15 16:04 258048 ----a-r- c:\windows\system32\hpzids01.dll
2009-07-07 13:25 . 2006-12-30 22:49 117760 ----a-w- c:\windows\system32\hpzll4v2.dll
2009-07-07 13:25 . 2006-12-06 06:02 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2009-07-07 13:24 . 2006-12-06 06:02 364544 ----a-r- c:\windows\system32\hppldcoi.dll
2009-07-07 13:24 . 2006-12-06 06:02 309760 ----a-r- c:\windows\system32\difxapi.dll
2009-07-07 13:24 . 2006-12-06 06:00 675840 ----a-r- c:\windows\system32\hpowiax3.dll
2009-07-07 13:24 . 2006-12-06 06:00 569344 ----a-r- c:\windows\system32\hpotscl3.dll
2009-07-07 13:24 . 2006-12-06 06:00 294912 ----a-r- c:\windows\system32\hpovst10.dll
2009-07-07 13:24 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-07-07 13:20 . 2009-07-13 16:51 -------- d-----w- c:\program files\HP
2009-07-07 13:20 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-07-07 12:23 . 2009-07-11 15:10 -------- d-----w- c:\program files\SWiSH Max2
2009-07-07 12:16 . 2004-03-29 22:23 90112 ------w- c:\windows\unvise32.exe
2009-07-05 16:20 . 2009-07-05 16:20 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2009-07-05 11:10 . 2009-07-05 11:28 -------- d-----w- c:\program files\eBook Workshop
2009-07-04 18:08 . 2007-07-29 22:53 117248 ----a-w- c:\windows\system32\RestoratorContextMenu.dll
2009-07-04 18:07 . 2009-07-04 18:07 -------- d-----w- c:\program files\Restorator 2006
2009-07-04 17:54 . 2009-07-04 17:54 286720 ------w- c:\windows\Setup1.exe
2009-07-04 17:54 . 2009-07-04 17:54 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-07-04 17:19 . 2009-07-04 17:18 720896 ----a-w- c:\windows\iun6002.exe
2009-07-04 11:40 . 2009-07-04 11:40 -------- d-----w- c:\documents and settings\mohammad\Application Data\AV Audio Recorder
2009-07-04 11:29 . 2005-04-25 20:01 458752 ----a-w- c:\windows\system32\NCTAudioRecord2.dll
2009-07-04 11:29 . 2005-03-28 22:54 479232 ----a-w- c:\windows\system32\NCTAudioVisualization2.dll
2009-07-04 11:29 . 2005-03-12 00:37 1986560 ----a-w- c:\windows\system32\NCTAudioFile2.dll
2009-07-04 10:51 . 2003-12-16 17:04 52736 ----a-w- c:\windows\system32\DrvTrNTm.dll
2009-07-04 10:51 . 2003-12-16 17:03 114688 ----a-w- c:\windows\system32\DrvTrNTl.dll
2009-07-03 22:48 . 2009-07-03 22:48 219664 ----a-w- c:\windows\system32\klogon.dll
2009-07-03 22:45 . 2009-07-03 22:45 27507 ----a-w- c:\windows\system32\drivers\klopp.dat
2009-07-01 22:00 . 2003-09-23 05:00 434252 ----a-w- c:\windows\system32\MSVCRTD.DLL
2009-07-01 21:59 . 2009-07-01 21:59 -------- d-----w- c:\program files\Speech Technology Center
2009-06-29 16:37 . 2009-06-29 16:37 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-29 16:36 . 2009-06-29 16:36 -------- d-----w- c:\program files\Conduit
2009-06-29 12:55 . 2006-12-14 02:51 86016 ----a-w- c:\windows\system32\etherh264.dll
2009-06-29 12:48 . 2009-06-29 16:20 -------- d-----w- c:\documents and settings\mohammad\Local Settings\Application Data\************
2009-06-29 12:48 . 2009-06-29 12:48 -------- d-----w- c:\documents and settings\mohammad\Local Settings\Application Data\Conduit
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-29 10:50 . 2009-05-15 00:55 -------- d-----w- c:\documents and settings\mohammad\Application Data\DMCache
2009-07-29 08:29 . 2009-07-29 08:29 1786 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2009-07-28 13:03 . 2009-04-28 10:31 -------- d-----w- c:\program files\MSECACHE
2009-07-28 11:58 . 2009-04-18 12:01 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-07-27 19:24 . 2009-05-15 00:55 -------- d-----w- c:\documents and settings\mohammad\Application Data\IDM
2009-07-27 18:50 . 2009-07-27 17:22 55976 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-27 12:17 . 2009-05-15 00:55 -------- d-----w- c:\program files\Internet Download Manager
2009-07-25 18:35 . 2009-04-18 14:41 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Messenger Plus!
2009-07-17 09:23 . 2009-04-17 23:32 57104 ----a-w- c:\documents and settings\mohammad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-10 20:18 . 2009-04-21 09:24 1744 ----a-w- c:\windows\system32\d3d9caps.dat
2009-07-06 12:04 . 2009-04-20 11:52 -------- d-----w- c:\program files\Google
2009-07-05 16:23 . 2009-04-17 19:23 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-01 21:59 . 2009-04-17 21:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-28 11:11 . 2009-06-28 11:11 -------- d-----w- c:\program files\ImageShack Corp
2009-06-26 16:50 . 2004-08-04 12:00 666624 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:50 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-24 11:21 . 2009-04-20 18:13 1632 ----a-w- c:\windows\system32\d3d8caps.dat
2009-06-23 17:43 . 2009-06-23 17:41 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\FarmFrenzy2
2009-06-16 14:36 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 21:01 . 2009-06-15 21:01 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
2009-06-12 09:03 . 2009-06-12 09:03 2926768 ----a-w- c:\documents and settings\mohammad\Application Data\IDM\idmupdt.exe
2009-06-07 19:38 . 2009-06-07 19:38 120240 ----a-w- c:\documents and settings\mohammad\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
2009-06-07 12:50 . 2009-06-07 12:50 198064 ----a-w- c:\documents and settings\mohammad\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-06-07 09:03 . 2009-06-07 09:03 95928 ----a-w- c:\documents and settings\mohammad\Application Data\IDM\idmmzcc01\components\idmmzcc.dll
2009-06-07 09:00 . 2009-06-07 09:00 165296 ----a-w- c:\documents and settings\mohammad\Application Data\IDM\idmmzcc02\components\idmmzcc.dll
2009-06-04 17:34 . 2009-06-04 17:24 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-06-03 19:09 . 2004-08-04 12:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-17 03:59 . 2009-05-17 03:59 19472 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2009-05-16 06:11 . 2009-05-16 06:12 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-16 06:10 . 2009-05-16 06:10 152576 ----a-w- c:\documents and settings\mohammad\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-14 00:46 . 2009-05-14 00:46 31760 ----a-w- c:\windows\system32\drivers\klim5.sys
2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\documents and settings\mohammad\Desktop\IDManCRACK.exe" [2007-12-21 2573744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-20 185872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-16 148888]
"avp"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-07-03 303376]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-7-28 118784]
path=
backup=
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4690:TCP"= 4690:TCP

iiymkcl
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [16/12/2008 06:41 ص 33808]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [20/02/2008 09:11 م 33800]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/05/2009 03:46 ص 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [17/05/2009 06:59 ص 19472]
S2 gupdate1c9c26257df1f96;خدمة تحديث Google (gupdate1c9c26257df1f96);c:\program files\Google\Update\GoogleUpdate.exe [21/04/2009 12:19 م 133104]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [22/04/2009 05:14 م 33176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
xntbshodz
.
Contents of the 'Scheduled Tasks' folder
2009-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-21 09:19]
2009-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-21 09:19]
2009-07-29 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-28 05:18]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{F4F10C1D-87C7-404A-B4B3-000000000000} - c:\progra~1\DAP\SBSearch.dll
URLSearchHooks-{09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - c:\program files\************\tb4sh1.dll
BHO-{09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - c:\program files\************\tb4sh1.dll
Toolbar-{09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - c:\program files\************\tb4sh1.dll
WebBrowser-{09EC805C-CB2E-4D53-B0D3-A75A428B81C7} - c:\program files\************\tb4sh1.dll
HKU-Default-Run-Yahoo Messengger - c:\windows\system32\scvshosts.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.qa/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Download all links with IDM - c:\documents and settings\mohammad\Desktop\IEGetAll.htm
IE: Download FLV video content with IDM - c:\documents and settings\mohammad\Desktop\IEGetVL.htm
IE: Download with IDM - c:\documents and settings\mohammad\Desktop\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-29 13:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1482476501-1220945662-725345543-1003\Software\Microsoft\Speech\AudioOutput\TokenEnums\MMAudioOut\ B1'!) *.7 *'DEH/E *#*0*\Attributes]
"Vendor"="Microsoft"
"Technology"="MMSys"
[HKEY_USERS\S-1-5-21-1482476501-1220945662-725345543-1003\Software\Microsoft\Speech\AudioOutput\TokenEnums\MMAudioOut\ B1'!) *.7 *'DEH/E *#*0*\UI\AudioVolume]
"CLSID"="{364D8E0B-67CB-4547-9948-9E7F1B1743ED}"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):5c,80,c5,b5,a9,ef,2e,f2,9b,d7,c2,5a,64,2a,cb,f5,91,81,05,1f,93,
1b,5a,70,74,6d,dc,81,33,19,a6,11,ce,ee,dc,78,a6,b3,f5,74,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6056244f-f7d6-42df-911d-070129c54bc0}]
@Denied: (Full) (Everyone)
"Model"=dword:000000bd
"Therad"=dword:00000001
"MData"=hex(0):cb,9b,ad,ef,27,7d,29,69,f5,02,f0,76,aa,4a,f1,7c,d3,d9,67,7f,6a,
4b,7b,ad,04,7a,b1,b5,76,9b,27,47,26,36,da,2f,30,9c,4b,a8,3d,d7,97,f8,4e,7e,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):10,c3,f3,f6,f0,be,8c,e3,6b,bb,1f,70,b1,7f,0d,98,be,8d,e6,18,94,
b2,94,ab,4c,22,f4,90,a5,4a,2b,90,96,c5,41,c4,8e,e9,f1,f4,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{836065e0-54b6-4ea6-bcc3-52602ed37396}]
@Denied: (Full) (Everyone)
"Model"=dword:0000009d
"Therad"=dword:00000018
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ےےےےہ•€|ù•A~*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3088)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\WinZip\WZQKPICK.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-29 13:58 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-29 10:56
Pre-Run: 14,321,651,712 bytes free
Post-Run: 14,335,176,704 bytes free
297 --- E O F --- 2009-07-29 19:51