ComboFix 09-07-29.03 - ibrahim 30-Jul-09 3:37.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.1023.449 [GMT 3:00]
Running from: c:\documents and settings\ibrahim\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\\setup.exe
c:\program files\WinPCap
c:\windows\Installer\2a1625.msi
c:\windows\Installer\39a874.msi
c:\windows\Installer\cc30a.msi
c:\windows\Installer\cc368.msi
.
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-30 )))))))))))))))))))))))))))))))
.
2009-07-30 00:19 . 2009-07-30 00:19 -------- d-----w- c:\program files\Trend Micro
2009-07-17 17:24 . 2009-07-06 21:16 2301208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avguiadv.dll
2009-07-17 17:24 . 2009-07-06 21:16 3403032 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-07-17 17:24 . 2009-07-06 21:16 353048 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgxch32.dll
2009-07-12 11:48 . 2009-07-06 21:16 2054424 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-07-12 11:48 . 2009-07-06 21:16 2167576 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgresf.dll
2009-07-06 21:13 . 2009-07-04 17:52 1085208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-07-06 21:13 . 2009-07-04 17:52 1454360 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-30 00:47 . 2008-08-20 16:39 -------- d-----w- c:\documents and settings\ibrahim\Application Data\DMCache
2009-07-30 00:43 . 2008-11-02 20:55 -------- d-----w- c:\documents and settings\ibrahim\Application Data\POP Peeper
2009-07-29 00:13 . 2009-04-05 23:08 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-29 00:00 . 2009-02-04 20:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-20 22:57 . 2007-05-15 21:28 -------- d-----w- c:\program files\DU Meter
2009-07-10 21:11 . 2009-06-19 23:17 314712 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\threatwork.exe
2009-07-10 21:11 . 2009-06-19 23:17 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\savapibridge.dll
2009-07-10 21:11 . 2009-06-19 23:17 169312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lavamessage.dll
2009-07-10 21:11 . 2009-06-19 23:17 348496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lavalicense.dll
2009-07-06 21:16 . 2009-01-28 12:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-06 21:16 . 2008-08-26 22:02 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-06 21:16 . 2008-08-26 22:02 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-03 17:09 . 2004-12-31 00:17 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-22 22:04 . 2009-06-22 22:04 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2009-06-22 22:04 . 2009-06-22 22:04 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2009-06-22 21:16 . 2007-05-22 16:23 -------- d-----w- c:\documents and settings\ibrahim\Application Data\Nokia
2009-06-22 21:09 . 2009-06-22 21:09 -------- d-----w- c:\program files\Common Files\PCSuite
2009-06-22 21:08 . 2008-02-06 13:13 -------- d-----w- c:\program files\Common Files\Nokia
2009-06-22 21:07 . 2007-05-22 16:23 -------- d-----w- c:\program files\DIFX
2009-06-22 21:07 . 2009-06-22 21:07 -------- d-----w- c:\program files\PC Connectivity Solution
2009-06-22 21:06 . 2008-02-06 13:12 -------- d-----w- c:\program files\Nokia
2009-06-22 21:06 . 2007-05-22 16:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-06-22 21:05 . 2009-06-22 21:05 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\pcswpcsi.exe
2009-06-22 21:05 . 2009-06-22 21:05 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstCCD.exe
2009-06-22 21:05 . 2009-06-22 21:05 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-06-22 21:05 . 2009-06-22 21:05 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstPCS.exe
2009-06-22 21:04 . 2009-06-22 21:06 33856936 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Nokia_PC_Suite_7_1_30_8_ara.exe
2009-06-22 19:52 . 2009-06-22 19:52 -------- d-----w- c:\program files\BandRich
2009-06-16 14:36 . 2004-12-31 00:17 119808 ------w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-12-31 00:17 81920 ------w- c:\windows\system32\fontsub.dll
2009-06-15 21:14 . 2007-05-15 22:21 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-06-15 21:14 . 2009-06-15 21:14 -------- d-----w- c:\program files\Zone Labs
2009-06-15 21:02 . 2009-06-15 21:02 2418889 ----a-w- c:\documents and settings\ibrahim\Application Data\IDM\DwnlData\ibrahim\ZASPSetup_80_400_020_en_414\ZASPSetup_80_400_020_en.exe
2009-06-15 20:55 . 2009-06-14 22:24 -------- d-----w- c:\program files\uTorrent
2009-06-15 00:01 . 2009-06-15 00:01 -------- d-----w- c:\program files\Advanced Port Scanner
2009-06-14 19:44 . 2009-06-14 19:43 -------- d-----w- c:\program files\FreeMeter
2009-06-13 23:41 . 2009-05-05 12:12 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverScanner
2009-06-13 21:56 . 2009-06-13 21:56 708796 ----a-w- c:\documents and settings\ibrahim\Application Data\IDM\DwnlData\ibrahim\IE8-WindowsXP-x86-ENU_409\IE8-WindowsXP-x86-ENU.exe
2009-06-11 23:39 . 2009-06-11 23:24 -------- d-----w- c:\program files\AirSnare
2009-06-11 17:06 . 2009-04-05 22:32 286720 ------w- c:\windows\Setup1.exe
2009-06-10 00:31 . 2005-01-22 19:34 -------- d-----w- c:\program files\Java
2009-06-10 00:30 . 2009-06-10 00:30 152576 ----a-w- c:\documents and settings\ibrahim\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-10 00:13 . 2008-12-30 00:05 -------- d-----w- c:\program files\Windows Desktop Search
2009-06-08 23:53 . 2009-06-08 23:53 -------- d-----w- c:\program files\Moo0
2009-06-05 22:11 . 2009-06-05 22:11 669806 ----a-w- c:\documents and settings\ibrahim\Application Data\IDM\DwnlData\ibrahim\WindowsXP-KB835935-SP2-ARA_397\WindowsXP-KB835935-SP2-ARA.exe
2009-06-03 19:09 . 2004-12-31 00:17 1291264 ------w- c:\windows\system32\quartz.dll
2009-06-02 23:41 . 2009-01-16 21:28 -------- d-----w- c:\program files\QuickTime
2009-06-02 23:40 . 2009-06-02 23:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-02 21:24 . 2009-06-02 21:23 106945 ----a-w- c:\documents and settings\ibrahim\Application Data\IDM\DwnlData\ibrahim\klcodec485m_377\klcodec485m.exe
2009-05-29 20:40 . 2009-05-29 20:40 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2009-05-29 20:40 . 2009-02-07 22:40 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-05-24 21:24 . 2008-05-26 19:18 350208 ----a-w- c:\windows\system32\mssph.dll
2009-05-21 08:33 . 2009-01-07 23:14 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-12 12:12 . 2007-05-16 03:14 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2009-05-11 09:47 . 2009-05-11 09:47 1302600 ----a-w- c:\windows\system32\WUDFUpdate_01007.dll
2009-05-07 15:32 . 2004-12-31 00:17 345600 ------w- c:\windows\system32\localspl.dll
2009-05-05 12:17 . 2009-05-05 12:16 2227304 ----a-w- c:\documents and settings\ibrahim\Application Data\Uniblue\DriverScanner\Download\pci_ven_8086_dev_24488_1_0_1002.exe
2009-05-03 11:32 . 2009-04-05 22:31 73216 ------w- c:\windows\ST6UNST.EXE
2009-05-02 09:35 . 2009-03-24 11:58 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2006-09-16 13:20 . 2006-09-16 13:14 1880140 ----a-w- c:\program files\Anti NetCut.CAB
2006-09-16 13:20 . 2006-09-16 13:14 3808 ----a-w- c:\program files\SETUP.LST
2003-08-27 11:19 . 2008-07-02 23:47 36963 ----a-r- c:\program files\Common Files\SM1updtr.dll
2009-07-11 00:56 . 2008-06-18 15:17 137208 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"POP Peeper"="c:\program files\POP Peeper\POPPeeper.exe" [2009-01-22 1470464]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-01-26 2745776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2005-01-14 352256]
"DockMsgFrom"="c:\program files\Toshiba\Toshiba Applet\DockMsgFrom.exe" [2004-11-11 114688]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-01-14 5525504]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 151552]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 385024]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2004-10-15 356352]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2005-02-01 1469952]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"TMEPROP"="c:\program files\Toshiba\Toshiba Applet\TMEPROP.exe" [2005-01-15 253952]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-06 1948440]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-10 520024]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-28 185872]
"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-01-21 266240]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-01-14 1490944]
"TFncKy"="TFncKy.exe" [BU]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-02-17 88363]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
c:\documents and settings\ibrahim\Start Menu\Programs\StartUp\
FreeMeter.lnk - c:\program files\FreeMeter\FreeMeter.exe [2009-6-14 614400]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
PC Health.lnk - c:\program files\TOSHIBA\TOSHIBA Management Console\TOSHealthLocalS.vbs [2009-1-7 3531]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2004-12-31 155648]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 18:27 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-06 21:16 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"SM1BG"=c:\windows\SM1BG.EXE
"DMXLauncher"="c:\program files\Roxio\CinePlayer\DMXLauncher.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\TOSHIBA\\ConfigFree\\CFXFER.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [06-Feb-09 11:39 PM 64160]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [27-Aug-08 1:02 AM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [24-Mar-09 2:58 PM 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [28-Jan-09 3:06 PM 298776]
R2 BandLuxe_Service;BandLuxe Service;c:\program files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe [11-Feb-09 2:37 PM 87264]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [19-Jan-09 12:34 AM 1029456]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03-Nov-06 7:19 PM 13592]
R3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [19-Apr-04 3:01 PM 7808]
S2 gupdate1c987075eefd450;Google Update Service (gupdate1c987075eefd450);c:\program files\Google\Update\GoogleUpdate.exe [04-Feb-09 11:30 PM 133104]
S2 PPCLASS;PPCLASS; [x]
S2 PPSCAN;PPSCAN;c:\windows\system32\drivers\ppscan.sys [11-Jul-07 7:50 PM 91520]
S2 RoxLiveShare10;LiveShare P2P Server 10; [x]
S2 SessionLauncher;SessionLauncher; [x]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\drivers\br3gmdm.sys [24-Jun-09 12:47 AM 104448]
S3 iscFlash;iscFlash;\??\c:\docume~1\ibrahim\LOCALS~1\Temp\isc38tmp\iscflash.sys --> c:\docume~1\ibrahim\LOCALS~1\Temp\isc38tmp\iscflash.sys [?]
S3 WinRing0_1_2_0;WinRing0_1_2_0;\??\c:\program files\Moo0\SystemMonitor 1.41\WinRing0.sys --> c:\program files\Moo0\SystemMonitor 1.41\WinRing0.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 21:10]
2009-01-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
2009-07-30 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-04 14:36]
2009-07-29 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 20:29]
2009-07-30 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 16:20]
2009-07-12 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-11-27 00:11]
2009-01-04 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-11-27 00:11]
2009-07-29 c:\windows\Tasks\User_Feed_Synchronization-{0F6F0F68-7B2E-4B35-ABA6-6537C796D62C}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 01:31]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
WebBrowser-{1C3C959F-E7D6-4C68-9BDD-45FD278D36EB} - (no file)
WebBrowser-{DA2A3A76-03CE-4885-8DEF-EB1EE316C41E} - (no file)
WebBrowser-{072EA664-15C7-4F40-8DDE-284C99025ADE} - (no file)
HKCU-Run-Sonic RecordNow! - (no file)
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = local
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
DPF: ANB Direct - hxxp://www.anb.com.sa/onlinebanking/classes.cab
DPF: Microsoft XML Parser for Java -
DPF: {630F2610-7654-11D1-83E3-0080C71A8794} - hxxp://www.anb.com.sa/arabic/onlinebanking/anb.cab
FF - ProfilePath - c:\documents and settings\ibrahim\Application Data\Mozilla\Firefox\Profiles\spwdys2u.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - component: c:\documents and settings\ibrahim\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "
");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-30 03:46
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{362f81ed-200c-421a-be1f-11eff2ac574a}]
@Denied: (Full) (Everyone)
"Model"=dword:00000019
"Therad"=dword:00000015
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):b9,d1,5e,ed,4b,1c,7f,c7,d8,3e,ad,52,4a,90,83,57,2d,a9,df,c5,e5,
d5,38,d1,50,15,82,dc,d1,26,07,41,3f,38,87,8f,ab,1e,c2,53,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):32,d5,eb,d7,2a,fb,71,23,c2,e4,52,a7,66,19,49,f3,9c,26,c9,ec,1a,
de,b0,0f,71,30,26,b9,25,c7,6c,fa,b9,a5,4f,51,07,c7,3a,3e,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{97981199-118a-4ebc-8072-df283fe01802}]
@Denied: (Full) (Everyone)
"Model"=dword:0000005b
"Therad"=dword:0000001b
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(952)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
- - - - - - - > 'explorer.exe'(5568)
c:\windows\system32\WININET.dll
c:\windows\system32\nview.dll
c:\program files\Toshiba\Toshiba Applet\TMEEJDLL.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\program files\Internet Download Manager\idmmkb.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ara.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
c:\windows\system32\ZoneLabs\vsmon.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Intel\Wireless\Bin\OProtSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
c:\program files\TOSHIBA\TOSHIBA Applet\tme3srv.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\wwSecure.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\TPSBattM.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2009-07-30 3:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-30 00:53
Pre-Run: 66,051,534,848 bytes free
Post-Run: 66,081,423,360 bytes free
374 --- E O F --- 2009-07-28 22:44