ComboFix 09-07-29.04 - ASH 07/31/2009 11:22.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.446.208 [GMT 3:00]
Running from: c:\documents and settings\ASH\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\ASH\Application Data\tazebama
c:\documents and settings\ASH\Application Data\tazebama\tazebama.log
c:\documents and settings\ASH\Application Data\tazebama\zPharaoh.dat
c:\windows\Installer\1a495ec.msp
c:\windows\Installer\c18a91.msp
c:\windows\system32\kakle.dll
C:\zPharaoh.exe
D:\Autorun.inf
D:\zPharaoh.exe
E:\Autorun.inf
E:\zPharaoh.exe
.
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-31 )))))))))))))))))))))))))))))))
.
2009-07-31 08:10 . 2009-07-31 08:10 -------- dc----w- c:\program files\Trend Micro
2009-07-31 07:33 . 2009-07-31 07:33 -------- dc----w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-07-31 06:27 . 2009-07-31 06:27 -------- dc----w- c:\windows\LastGood
2009-07-31 06:14 . 2009-07-31 06:14 198064 -c--a-w- c:\documents and settings\ASH\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-07-31 06:14 . 2009-07-31 06:36 -------- dc----w- c:\program files\Internet Download Manager
2009-07-31 05:51 . 2009-07-31 05:51 -------- dc----w- c:\program files\Windows Live
2009-07-31 05:51 . 2009-07-31 05:51 -------- dc----w- c:\program files\Microsoft Sync Framework
2009-07-31 05:51 . 2009-07-31 05:51 -------- dc----w- c:\program files\Windows Live SkyDrive
2009-07-31 05:51 . 2009-07-31 05:51 -------- dc----w- c:\program files\Microsoft SQL Server Compact Edition
2009-07-31 03:20 . 2009-07-31 03:20 34304 -c--a-w- c:\documents and settings\ASH\Application Data\Thinstall\Microsoft Office FrontPage 2003\e9930ef5999e99c7051676i\AcroRd32Info.exe
2009-07-31 03:20 . 2009-07-31 03:20 34304 -c--a-w- c:\documents and settings\ASH\Application Data\Thinstall\Microsoft Office FrontPage 2003\1000000b00002i\verclsid.exe
2009-07-31 02:13 . 2009-07-31 02:13 -------- dc----w- c:\windows\system32\ar
2009-07-31 02:13 . 2009-07-31 02:13 -------- dc----w- c:\windows\l2schemas
2009-07-31 02:13 . 2009-07-31 02:13 -------- dc----w- c:\windows\system32\bits
2009-07-31 02:10 . 2009-07-31 02:10 -------- dc----w- c:\windows\ServicePackFiles
2009-07-31 01:57 . 2009-07-31 01:57 -------- dc----w- c:\program files\Microsoft Silverlight
2009-07-30 11:10 . 2008-04-14 15:59 221184 -c--a-w- c:\windows\system32\wmpns.dll
2009-07-30 11:02 . 2009-07-30 11:02 47104 -c----w- c:\windows\AKDeInstall.exe
2009-07-30 11:01 . 2009-07-30 11:02 -------- dc----w- c:\program files\Java
2009-07-30 11:01 . 2009-07-30 11:01 -------- dc----w- c:\program files\Common Files\Java
2009-07-30 11:00 . 2009-07-30 11:00 -------- dc----w- c:\documents and settings\ASH\Local Settings\Application Data\Sun
2009-07-30 08:56 . 2009-07-31 01:37 -------- dc----w- c:\documents and settings\All Users\Application Data\Avira
2009-07-30 08:02 . 2009-07-30 08:02 -------- dc----w- c:\documents and settings\All Users\Application Data\Adobe Systems
2009-07-30 08:02 . 2009-07-30 08:02 -------- dc----w- c:\program files\Common Files\Adobe Systems Shared
2009-07-30 06:42 . 2009-07-30 06:42 34304 -c--a-w- c:\documents and settings\ASH\Application Data\Thinstall\Microsoft Office FrontPage 2003\10000001600002i\msiexec.exe
2009-07-29 20:23 . 2009-07-31 06:26 -------- dc----w- c:\program files\Hotspot Shield
2009-07-29 12:38 . 2009-07-03 16:55 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-29 12:38 . 2009-07-03 16:55 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-07-29 11:52 . 2009-07-29 11:52 -------- dc----w- c:\program files\MSXML 4.0
2009-07-29 04:40 . 2009-07-29 04:40 34304 -c--a-w- c:\documents and settings\ASH\Application Data\Thinstall\Microsoft Office FrontPage 2003\30000000be00002i\DW20.EXE
2009-07-29 03:39 . 2009-07-29 03:40 -------- dc----w- c:\program files\WMV9_VCM
2009-07-29 03:39 . 2009-07-29 03:40 -------- dc----w- c:\documents and settings\ASH\Local Settings\Application Data\Xara
2009-07-29 03:39 . 2009-07-29 03:39 -------- dc----w- c:\program files\Common Files\Xara
2009-07-26 10:58 . 2009-07-30 10:23 -------- dc----w- c:\program files\USB Disk Security
2009-07-25 09:09 . 2009-07-25 09:09 -------- dc----w- c:\documents and settings\ASH\Local Settings\Application Data\Identities
2009-07-24 23:56 . 2009-07-27 00:59 -------- dc----w- c:\documents and settings\ASH\Local Settings\Application Data\Netlog
2009-07-24 21:21 . 2009-07-24 21:49 -------- dc----w- c:\windows\SxsCaPendDel
2009-07-24 21:02 . 2009-07-30 10:21 -------- dc----w- c:\program files\DynDNS Updater
2009-07-24 21:02 . 2009-07-24 21:02 -------- dc----w- c:\documents and settings\All Users\Application Data\DynDNS
2009-07-24 08:28 . 2009-07-30 09:30 -------- dc----w- c:\program files\No-IP
2009-07-22 20:14 . 2009-07-31 06:30 -------- dc----w- c:\documents and settings\ASH\Application Data\IDM
2009-07-22 19:24 . 2009-07-22 19:24 -------- dc----w- c:\program files\dvdup
2009-07-22 08:55 . 2009-07-31 08:21 -------- dc----w- c:\documents and settings\ASH\Application Data\DMCache
2009-07-21 05:11 . 2009-07-30 10:20 -------- dc----w- c:\program files\Any Audio Converter
2009-07-20 21:11 . 2004-08-03 21:38 700928 -c----w- c:\windows\system32\drivers\ati2mtag.sys
2009-07-20 18:46 . 2009-07-20 18:46 -------- dc----w- c:\documents and settings\ASH\Application Data\Windows Live Writer
2009-07-20 18:46 . 2009-07-20 18:47 -------- dc----w- c:\documents and settings\ASH\Local Settings\Application Data\Windows Live Writer
2009-07-20 16:20 . 2009-07-20 16:20 592 -c--a-w- c:\windows\chgkey.vbs
2009-07-20 16:18 . 2009-07-20 16:18 -------- dc----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-07-20 06:32 . 2009-07-20 06:32 -------- dc----w- c:\program files\Common Files\xing shared
2009-07-20 06:32 . 2009-07-30 10:51 348160 -c--a-w- c:\windows\system32\msvcr71.dll
2009-07-20 06:32 . 2009-07-30 10:51 499712 -c--a-w- c:\windows\system32\msvcp71.dll
2009-07-20 05:44 . 2009-07-20 05:44 -------- dc----w- c:\documents and settings\ASH\Application Data\Media Player Classic
2009-07-20 05:34 . 2009-07-20 05:34 10240 -c--a-w- c:\documents and settings\ASH\Application Data\GRETECH\GomPlayer\GrLauncherTempSetup.exe
2009-07-20 05:34 . 2007-03-22 10:46 126976 -c--a-w- c:\documents and settings\ASH\Application Data\GRETECH\GomPlayer\GrLauncher.exe
2009-07-19 09:26 . 2009-07-19 09:26 34304 -c--a-w- c:\documents and settings\ASH\Application Data\Thinstall\Microsoft Office FrontPage 2003\4000004d00002i\MDM.EXE
2009-07-19 09:26 . 2009-07-26 06:59 -------- dc----w- c:\documents and settings\ASH\Application Data\Thinstall
2009-07-19 09:23 . 2009-07-19 09:23 -------- dc-h--w- c:\windows\PIF
2009-07-18 06:08 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-07-18 06:08 . 2009-03-06 14:20 283136 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-07-18 06:08 . 2009-02-09 11:22 2190592 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-07-18 06:08 . 2009-02-09 11:21 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-07-18 06:08 . 2009-02-09 10:51 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-07-18 06:08 . 2009-02-09 10:51 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-07-18 06:08 . 2009-02-09 10:51 723456 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2009-07-18 06:08 . 2009-02-09 10:51 681472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-07-18 06:08 . 2009-02-09 10:51 693760 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-07-18 06:08 . 2009-02-09 10:51 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-07-18 06:08 . 2009-02-09 11:22 2146816 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-07-18 06:08 . 2009-02-09 11:22 2025472 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-07-18 05:53 . 2008-06-14 17:31 271616 -c----w- c:\windows\system32\drivers\bthport.sys
2009-07-18 05:53 . 2008-06-14 17:31 271616 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-07-18 05:25 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2009-07-18 05:24 . 2008-04-21 21:14 215040 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-07-18 05:22 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-07-18 05:21 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-07-18 05:19 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-07-18 05:10 . 2008-10-15 16:35 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-07-18 04:57 . 2008-10-16 11:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-07-18 04:57 . 2008-10-16 11:06 208744 -c--a-w- c:\windows\system32\muweb.dll
2009-07-18 04:08 . 2008-04-14 15:59 21504 -c--a-w- c:\windows\system32\hidserv.dll
2009-07-18 04:08 . 2008-04-14 15:40 14592 -c--a-w- c:\windows\system32\drivers\kbdhid.sys
2009-07-18 04:08 . 2008-04-13 18:45 32128 -c--a-w- c:\windows\system32\drivers\usbccgp.sys
2009-07-17 11:33 . 2009-07-30 10:21 -------- dc----w- c:\program files\FileZilla FTP Client
2009-07-17 11:31 . 2009-07-30 10:48 -------- dc----w- c:\documents and settings\ASH\Application Data\FileZilla
2009-07-17 10:39 . 2009-07-17 10:39 -------- dcsh--w- c:\documents and settings\ASH\IECompatCache
2009-07-17 10:39 . 2009-07-17 10:39 -------- dcsh--w- c:\documents and settings\ASH\PrivacIE
2009-07-17 10:39 . 2009-07-17 10:39 -------- dcsh--w- c:\documents and settings\LocalService\IETldCache
2009-07-17 10:39 . 2009-07-17 10:39 -------- dcsh--w- c:\documents and settings\ASH\IETldCache
2009-07-17 10:37 . 2009-07-17 10:37 -------- dc----w- c:\windows\ie8updates
2009-07-17 10:35 . 2009-07-31 02:13 -------- dc----w- c:\windows\system32\ar-SA
2009-07-17 10:35 . 2009-07-17 10:35 -------- dc-h--w- c:\windows\ie8
2009-07-17 10:01 . 2009-07-19 10:16 -------- dc----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-07-17 09:55 . 2009-07-30 09:14 -------- dc----w- c:\documents and settings\All Users\Application Data\Cast ping base frag
2009-07-17 09:54 . 2009-07-30 10:09 -------- dc----w- c:\documents and settings\ASH\Application Data\dvdup
2009-07-17 09:54 . 2009-07-30 10:20 -------- dc----w- c:\program files\Circle Developemet
2009-07-17 09:54 . 2009-07-30 10:22 -------- dc----w- c:\program files\Messenger Plus! Live
2009-07-17 05:00 . 2009-07-30 06:36 -------- dc----w- c:\documents and settings\ASH\Tracing
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-31 02:55 . 2009-07-17 01:48 78192 -c--a-w- c:\documents and settings\ASH\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-31 02:21 . 2004-08-04 12:00 58586 ----a-w- c:\windows\system32\perfc001.dat
2009-07-31 02:21 . 2004-08-04 12:00 328222 ----a-w- c:\windows\system32\perfh001.dat
2009-07-30 11:04 . 2009-07-17 02:29 -------- dc----w- c:\program files\K-Lite Codec Pack
2009-07-30 11:02 . 2009-07-17 02:36 -------- dc----w- c:\program files\mpegable
2009-07-30 10:52 . 2009-07-17 02:35 -------- dc----w- c:\program files\Common Files\Real
2009-07-30 10:23 . 2009-07-17 02:31 -------- dc----w- c:\program files\Real_SC
2009-07-30 10:23 . 2009-07-17 02:33 -------- dc----w- c:\program files\QuickTime
2009-07-30 10:21 . 2009-07-17 02:32 -------- dc----w- c:\program files\Google
2009-07-30 10:21 . 2009-07-17 02:37 -------- dc----w- c:\program files\FLV Player
2009-07-30 08:06 . 2009-07-17 02:30 -------- dc----w- c:\program files\Common Files\Adobe
2009-07-29 03:39 . 2009-07-17 02:33 -------- dc-h--w- c:\program files\InstallShield Installation Information
2009-07-24 23:56 . 2009-07-17 02:33 -------- dc----w- c:\program files\iTunes
2009-07-24 20:16 . 2009-07-17 02:34 -------- dc----w- c:\documents and settings\ASH\Application Data\Apple Computer
2009-07-19 05:38 . 2009-07-17 01:30 86327 -c--a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-17 04:55 . 2009-07-17 04:55 -------- dc----w- c:\program files\Microsoft
2009-07-17 04:53 . 2009-07-17 04:53 -------- dc----w- c:\program files\Common Files\Windows Live
2009-07-17 03:25 . 2009-07-17 03:25 -------- dc----w- c:\documents and settings\ASH\Application Data\Yahoo!
2009-07-17 02:47 . 2009-07-17 02:33 -------- dc----w- c:\program files\Common Files\InstallShield
2009-07-17 02:44 . 2009-07-17 02:44 -------- dc----w- c:\program files\Microsoft.NET
2009-07-17 02:38 . 2009-07-17 02:38 -------- dc----w- c:\documents and settings\ASH\Application Data\vlc
2009-07-17 02:37 . 2009-07-17 02:37 -------- dc----w- c:\program files\VideoLAN
2009-07-17 02:35 . 2009-07-17 02:35 -------- dc----w- c:\program files\Real
2009-07-17 02:33 . 2009-07-17 02:33 -------- dc----w- c:\program files\iPod
2009-07-17 02:33 . 2009-07-17 02:33 -------- dc----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-17 02:32 . 2009-07-17 02:32 -------- dc----w- c:\documents and settings\All Users\Application Data\GRETECH
2009-07-17 02:32 . 2009-07-17 02:32 -------- dc----w- c:\documents and settings\ASH\Application Data\GRETECH
2009-07-17 02:32 . 2009-07-17 02:32 -------- dc----w- c:\program files\GRETECH
2009-07-17 02:31 . 2009-07-17 02:31 90112 -c--a-w- c:\windows\system32\agsaami.dll
2009-07-17 02:31 . 2009-07-17 02:31 610304 -c--a-w- c:\windows\system32\agsaamg.dll
2009-07-17 02:31 . 2009-07-17 02:31 372736 -c--a-w- c:\windows\system32\agsaamc.dll
2009-07-17 02:31 . 2009-07-17 02:31 2535424 -c--a-w- c:\windows\system32\agsaamj.dll
2009-07-17 02:31 . 2009-07-17 02:31 1986560 -c--a-w- c:\windows\system32\akll.dll
2009-07-17 02:31 . 2009-07-17 02:31 1245184 -c--a-w- c:\windows\system32\bkll.dll
2009-07-17 02:31 . 2009-07-17 02:31 1212416 -c--a-w- c:\windows\system32\ckll.dll
2009-07-17 01:31 . 2009-07-17 01:31 -------- dc----w- c:\program files\microsoft frontpage
2009-07-17 01:28 . 2009-07-17 01:28 22144 -c--a-w- c:\windows\system32\emptyregdb.dat
2009-07-15 00:01 . 2009-07-15 00:01 25472 -c--a-w- c:\windows\system32\drivers\tap0901.sys
2009-07-03 16:55 . 2004-08-04 12:00 915456 -c--a-w- c:\windows\system32\wininet.dll
2009-07-02 02:34 . 2009-07-02 02:34 33840 -c--a-w- c:\windows\system32\drivers\HssDrv.sys
2009-06-16 14:36 . 2004-08-04 12:00 81920 -c--a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 12:00 119808 -c--a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:10 . 2004-08-04 12:00 1289216 -c--a-w- c:\windows\system32\quartz.dll
2009-05-07 15:32 . 2004-08-04 12:00 345600 -c--a-w- c:\windows\system32\localspl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-05-27 2815408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-02-08 278528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-07-17 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-07-20 198160]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_14\bin\jusched.exe" [2007-10-05 75256]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2005-03-07 53248]
"VTTrayp"="VTtrayp.exe" - c:\windows\system32\VTTrayp.exe [2005-10-31 163840]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-11-11 90112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
S3 SetupNTGLM7X;SetupNTGLM7X;\??\f:\ntglm7x.sys --> f:\NTGLM7X.sys [?]
S3 tap0901;TAP-Win32 Adapter V9;c:\windows\system32\drivers\tap0901.sys [15/07/2009 03:01 ص 25472]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - RSVP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-30 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-07-31 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-07-31 c:\windows\Tasks\User_Feed_Synchronization-{BD434E71-7D58-4FDF-933E-E4DBA6A8E803}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 01:31]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MsnMsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
HKCU-Run-Netlog Music Tool - c:\program files\Netlog Music Tool\NetlogMusicTool.exe
HKLM-Run-USB Antivirus - c:\program files\USB Disk Security\USBGuard.exe
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyServer = https=1045-1806-0605-0955-3112-9294
uInternet Settings,ProxyOverride = <local>
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-31 11:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{478bfc34-5ef4-491f-8c67-d0f1d1dcb88d}]
@Denied: (Full) (Everyone)
"Model"=dword:000000d3
"Therad"=dword:0000000a
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):bf,f3,67,83,b3,ee,26,44,68,f7,72,3a,79,77,a4,07,08,4d,dd,7e,cb,
9a,15,6d,6b,a5,1b,53,7b,79,e7,76,86,a5,ee,c6,0b,3e,7f,2d,00,00,00,00,00,00,\
.
Completion time: 2009-07-31 11:27
ComboFix-quarantined-files.txt 2009-07-31 08:27
Pre-Run: 1,186,045,952 bytes free
Post-Run: 2,213,023,744 bytes free
249 --- E O F --- 2009-07-31 02:18