ComboFix 09-10-08.04 - XPPRESP3 10/09/2009 17:57.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.495.211 [GMT 3:00]
Running from: c:\documents and settings\XPPRESP3\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\XPPRESP3\Application Data\addons.dat
c:\documents and settings\XPPRESP3\Application Data\tazebama
c:\documents and settings\XPPRESP3\Application Data\tazebama\tazebama.log
c:\documents and settings\XPPRESP3\Application Data\tazebama\zPharaoh.dat
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\program files\Search Settings
c:\program files\Search Settings\kb127\SearchSettingsRes409.dll
c:\program files\Search Settings\SearchSettings.exe
c:\windows\Installer\10246f5.msp
c:\windows\Installer\1024704.msp
c:\windows\Installer\1024712.msp
c:\windows\Installer\106190b.msp
c:\windows\Installer\106191a.msp
c:\windows\Installer\1061928.msp
c:\windows\Installer\1101e5a.msp
c:\windows\Installer\1101e69.msp
c:\windows\Installer\1101e78.msp
c:\windows\Installer\1101e87.msp
c:\windows\Installer\16f77d6.msp
c:\windows\Installer\16f77e5.msp
c:\windows\Installer\16f77f3.msp
c:\windows\Installer\19aaec.msp
c:\windows\Installer\19aafb.msp
c:\windows\Installer\19ab09.msp
c:\windows\Installer\1a081.msp
c:\windows\Installer\1a090.msp
c:\windows\Installer\1a09e.msp
c:\windows\Installer\1a46c1c.msp
c:\windows\Installer\1a46c2b.msp
c:\windows\Installer\1a46c39.msp
c:\windows\Installer\1a87f.msp
c:\windows\Installer\1a88e.msp
c:\windows\Installer\1a89c.msp
c:\windows\Installer\1bd11.msp
c:\windows\Installer\1bd20.msp
c:\windows\Installer\1c3b8.msp
c:\windows\Installer\1c3c7.msp
c:\windows\Installer\1c3d5.msp
c:\windows\Installer\1c5fa.msp
c:\windows\Installer\1c609.msp
c:\windows\Installer\1c619.msp
c:\windows\Installer\1c628.msp
c:\windows\Installer\1ce76.msp
c:\windows\Installer\1d0f7.msp
c:\windows\Installer\1d106.msp
c:\windows\Installer\1d11f.msp
c:\windows\Installer\1d973.msp
c:\windows\Installer\1d982.msp
c:\windows\Installer\1d992.msp
c:\windows\Installer\1d9a1.msp
c:\windows\Installer\1daca.msp
c:\windows\Installer\1dace.msp
c:\windows\Installer\1dad2.msp
c:\windows\Installer\1dc51.msp
c:\windows\Installer\1dc60.msp
c:\windows\Installer\1dc6e.msp
c:\windows\Installer\1e0d5.msp
c:\windows\Installer\1e0e4.msp
c:\windows\Installer\1e0f4.msp
c:\windows\Installer\1e103.msp
c:\windows\Installer\1e51e.msi
c:\windows\Installer\1f0e3.msp
c:\windows\Installer\1fa42d8.msp
c:\windows\Installer\1fa42e7.msp
c:\windows\Installer\1fa42f5.msp
c:\windows\Installer\1fab6.msp
c:\windows\Installer\1fac5.msp
c:\windows\Installer\1fad3.msp
c:\windows\Installer\2041f48.msp
c:\windows\Installer\2041f57.msp
c:\windows\Installer\2041f65.msp
c:\windows\Installer\22c6e88.msp
c:\windows\Installer\22c6e97.msp
c:\windows\Installer\22c6ea7.msp
c:\windows\Installer\22c6eb6.msp
c:\windows\Installer\2306c.msp
c:\windows\Installer\23946.msp
c:\windows\Installer\23955.msp
c:\windows\Installer\23963.msp
c:\windows\Installer\23d0200.msp
c:\windows\Installer\23d0211.msp
c:\windows\Installer\24fac.msp
c:\windows\Installer\255cc2.msp
c:\windows\Installer\255cd1.msp
c:\windows\Installer\255ce1.msp
c:\windows\Installer\255cf0.msp
c:\windows\Installer\2566c98.msp
c:\windows\Installer\2566ca7.msp
c:\windows\Installer\2566cb7.msp
c:\windows\Installer\2566cc6.msp
c:\windows\Installer\289d7.msp
c:\windows\Installer\289e6.msp
c:\windows\Installer\289f6.msp
c:\windows\Installer\28a05.msp
c:\windows\Installer\29e59.msp
c:\windows\Installer\29e68.msp
c:\windows\Installer\2a68ad9.msi
c:\windows\Installer\2b8684.msp
c:\windows\Installer\2b8693.msp
c:\windows\Installer\2b86a1.msp
c:\windows\Installer\2ba585.msp
c:\windows\Installer\2ba594.msp
c:\windows\Installer\2ba5a4.msp
c:\windows\Installer\2ba5b3.msp
c:\windows\Installer\2bfdb.msp
c:\windows\Installer\2bfea.msp
c:\windows\Installer\2bff050.msp
c:\windows\Installer\2bff05f.msp
c:\windows\Installer\2bff06e.msp
c:\windows\Installer\2bff07d.msp
c:\windows\Installer\2bff8.msp
c:\windows\Installer\2e1ab.msp
c:\windows\Installer\2e1bc.msp
c:\windows\Installer\32d9344.msp
c:\windows\Installer\32d9353.msp
c:\windows\Installer\32d9361.msp
c:\windows\Installer\33a5a.msp
c:\windows\Installer\33a69.msp
c:\windows\Installer\33a79.msp
c:\windows\Installer\33a88.msp
c:\windows\Installer\39dc8.msp
c:\windows\Installer\39dd7.msp
c:\windows\Installer\39de5.msp
c:\windows\Installer\422c25b.msp
c:\windows\Installer\422c26a.msp
c:\windows\Installer\422c27a.msp
c:\windows\Installer\422c289.msp
c:\windows\Installer\49576.msp
c:\windows\Installer\49585.msp
c:\windows\Installer\49595.msp
c:\windows\Installer\495a4.msp
c:\windows\Installer\4eaf8.msp
c:\windows\Installer\4eb09.msp
c:\windows\Installer\4f88f6.msp
c:\windows\Installer\4f8905.msp
c:\windows\Installer\4f8915.msp
c:\windows\Installer\4f8924.msp
c:\windows\Installer\554558.msp
c:\windows\Installer\858d7.msp
c:\windows\Installer\858e6.msp
c:\windows\Installer\858f4.msp
c:\windows\Installer\969a81.msp
c:\windows\Installer\969a90.msp
c:\windows\Installer\969aa0.msp
c:\windows\Installer\969aaf.msp
c:\windows\Installer\9b0a5.msp
c:\windows\Installer\9e6c36.msp
c:\windows\Installer\9e6c47.msp
c:\windows\Installer\a0237b.msp
c:\windows\Installer\a0238c.msp
c:\windows\Installer\a45cec8.msp
c:\windows\Installer\a45cf4f.msp
c:\windows\Installer\a7a905.msp
c:\windows\Installer\a7a914.msp
c:\windows\Installer\a7a924.msp
c:\windows\Installer\a7a933.msp
c:\windows\Installer\aca25.msp
c:\windows\Installer\aca34.msp
c:\windows\Installer\aca42.msp
c:\windows\Installer\b4184f.msp
c:\windows\Installer\c45589.msp
c:\windows\Installer\c45598.msp
c:\windows\Installer\c455a8.msp
c:\windows\Installer\c455b7.msp
c:\windows\Installer\e7276a.msp
c:\windows\Installer\e72779.msp
c:\windows\Installer\e72787.msp
c:\windows\Installer\f5645.msp
c:\windows\Installer\f5654.msp
c:\windows\Installer\f5664.msp
c:\windows\Installer\f5673.msp
c:\windows\Installer\f823fc.msp
c:\windows\Installer\f8240b.msp
c:\windows\Installer\f8241a.msp
c:\windows\Installer\f82429.msp
c:\windows\Installer\f898a0.msp
c:\windows\Installer\f898af.msp
c:\windows\Installer\f898bf.msp
c:\windows\Installer\f898ce.msp
c:\windows\Installer\fbac58.msp
c:\windows\Installer\fbac67.msp
c:\windows\Installer\fbac75.msp
c:\windows\system32\_000014_.tmp.dll
c:\windows\system32\Bifrost
c:\windows\system32\Bifrost\logg.dat
c:\windows\system32\Bifrost\server.exe
c:\windows\regedit.exe . . . is infected!!
c:\windows\explorer.exe . . . is infected!!
c:\windows\hh.exe . . . is infected!!
c:\windows\twunk_32.exe . . . is infected!!
Infected copy of c:\windows\winhlp32.exe was found and disinfected
Restored copy from - c:\windows\system32\winhlp32.exe
c:\windows\system32\ahui.exe . . . is infected!!
c:\windows\system32\arp.exe . . . is infected!!
c:\windows\system32\asr_pfu.exe . . . is infected!!
c:\windows\system32\calc.exe . . . is infected!!
c:\windows\system32\charmap.exe . . . is infected!!
c:\windows\system32\cipher.exe . . . is infected!!
c:\windows\system32\cmd.exe . . . is infected!!
c:\windows\system32\cscript.exe . . . is infected!!
c:\windows\system32\ddeshare.exe . . . is infected!!
c:\windows\system32\diskpart.exe . . . is infected!!
c:\windows\system32\dmadmin.exe . . . is infected!!
c:\windows\system32\dplaysvr.exe . . . is infected!!
c:\windows\system32\dpvsetup.exe . . . is infected!!
c:\windows\system32\dwwin.exe . . . is infected!!
c:\windows\system32\dxdiag.exe . . . is infected!!
c:\windows\system32\esentutl.exe . . . is infected!!
c:\windows\system32\eudcedit.exe . . . is infected!!
c:\windows\system32\freecell.exe . . . is infected!!
c:\windows\system32\fsquirt.exe . . . is infected!!
c:\windows\system32\gpupdate.exe . . . is infected!!
c:\windows\system32\iexpress.exe . . . is infected!!
c:\windows\system32\ipsec6.exe . . . is infected!!
c:\windows\system32\ipv6.exe . . . is infected!!
c:\windows\system32\logagent.exe . . . is infected!!
c:\windows\system32\logonui.exe . . . is infected!!
c:\windows\system32\mmc.exe . . . is infected!!
c:\windows\system32\mobsync.exe . . . is infected!!
c:\windows\system32\mplay32.exe . . . is infected!!
c:\windows\system32\mpnotify.exe . . . is infected!!
c:\windows\system32\mshearts.exe . . . is infected!!
c:\windows\system32\mspaint.exe . . . is infected!!
c:\windows\system32\mstsc.exe . . . is infected!!
c:\windows\system32\net.exe . . . is infected!!
c:\windows\system32\netdde.exe . . . is infected!!
c:\windows\system32\netsetup.exe . . . is infected!!
c:\windows\system32\netstat.exe . . . is infected!!
c:\windows\system32\ntbackup.exe . . . is infected!!
c:\windows\system32\ntsd.exe . . . is infected!!
c:\windows\system32\ntvdm.exe . . . is infected!!
c:\windows\system32\nwscript.exe . . . is infected!!
c:\windows\system32\odbcad32.exe . . . is infected!!
c:\windows\system32\odbcconf.exe . . . is infected!!
c:\windows\system32\ping6.exe . . . is infected!!
c:\windows\system32\powercfg.exe . . . is infected!!
c:\windows\system32\proquota.exe . . . is infected!!
c:\windows\system32\rdpclip.exe . . . is infected!!
c:\windows\system32\routemon.exe . . . is infected!!
c:\windows\system32\rtcshare.exe . . . is infected!!
c:\windows\system32\scardsvr.exe . . . is infected!!
c:\windows\system32\sdbinst.exe . . . is infected!!
c:\windows\system32\sessmgr.exe . . . is infected!!
Infected copy of c:\windows\system32\setup.exe was found and disinfected
Restored copy from - c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
c:\windows\system32\shrpubw.exe . . . is infected!!
c:\windows\system32\smbinst.exe . . . is infected!!
c:\windows\system32\smlogsvc.exe . . . is infected!!
c:\windows\system32\sndrec32.exe . . . is infected!!
c:\windows\system32\sndvol32.exe . . . is infected!!
c:\windows\system32\sol.exe . . . is infected!!
c:\windows\system32\spider.exe . . . is infected!!
c:\windows\system32\syncapp.exe . . . is infected!!
c:\windows\system32\sysocmgr.exe . . . is infected!!
c:\windows\system32\taskmgr.exe . . . is infected!!
c:\windows\system32\tcpsvcs.exe . . . is infected!!
c:\windows\system32\tlntsvr.exe . . . is infected!!
c:\windows\system32\tracerpt.exe . . . is infected!!
c:\windows\system32\tracert6.exe . . . is infected!!
c:\windows\system32\tscupgrd.exe . . . is infected!!
c:\windows\system32\userinit.exe . . . is infected!!
c:\windows\system32\usrmlnka.exe . . . is infected!!
c:\windows\system32\usrprbda.exe . . . is infected!!
c:\windows\system32\usrshuta.exe . . . is infected!!
c:\windows\system32\wextract.exe . . . is infected!!
c:\windows\system32\winchat.exe . . . is infected!!
c:\windows\system32\winmine.exe . . . is infected!!
c:\windows\system32\wscript.exe . . . is infected!!
c:\windows\system32\wuauclt1.exe . . . is infected!!
c:\windows\system32\Restore\rstrui.exe . . . is infected!!
.
((((((((((((((((((((((((( Files Created from 2009-09-09 to 2009-10-09 )))))))))))))))))))))))))))))))
.
2009-10-09 14:04 . 2008-12-11 05:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-10-09 14:03 . 2009-08-24 11:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-10-09 14:03 . 2009-08-19 08:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-10-09 14:03 . 2009-10-09 14:13 -------- d-----w- c:\program files\Common Files\PC Tools
2009-10-09 14:03 . 2008-12-10 08:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-10-09 14:03 . 2009-10-09 14:59 -------- d-----w- c:\program files\Spyware Doctor
2009-10-09 14:03 . 2009-10-09 14:03 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\PC Tools
2009-10-09 14:03 . 2009-10-09 14:03 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-10-08 03:47 . 2009-10-08 03:47 8192 ----a-w- c:\windows\Rpoint.exe
2009-10-08 03:36 . 2009-10-08 03:36 737280 ----a-w- c:\windows\iun6002.exe
2009-10-08 03:36 . 2009-10-09 14:49 -------- d-----w- C:\spywarebegone
2009-10-07 15:32 . 2009-10-07 15:32 -------- d-----w- c:\program files\SuperCleaner
2009-10-07 15:32 . 2009-10-07 15:32 7680 ----a-w- C:\DmarMessengerPass.exe
2009-10-07 15:23 . 2009-10-07 15:23 -------- d-----w- c:\program files\XoftSpySE
2009-10-06 11:14 . 2009-10-06 14:07 -------- d-----w- c:\documents and settings\XPPRESP3\PassTools
2009-09-30 16:16 . 2009-04-28 20:20 129520 ------w- c:\windows\system32\pxafs.dll
2009-09-24 07:49 . 2009-09-24 07:50 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\Octoshape
2009-09-16 12:12 . 2009-08-05 19:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-09-16 12:09 . 2009-09-16 12:09 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-09 21:51 . 2009-06-21 22:04 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-09 17:43 . 2009-09-09 17:43 -------- d-----w- c:\program files\First dog deaf
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-09 16:24 . 2008-04-08 01:16 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-09 16:24 . 2007-12-28 22:47 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\DMCache
2009-10-07 15:16 . 2008-04-07 22:23 -------- d-----w- c:\program files\Registry Fast
2009-10-03 00:01 . 2008-11-11 18:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-30 21:45 . 2007-12-24 07:33 506488 -c--a-w- c:\documents and settings\XPPRESP3\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-30 18:06 . 2009-01-25 15:52 -------- d-----w- c:\program files\Uninstall Tool
2009-09-26 21:46 . 2009-04-15 13:38 -------- d-----w- c:\program files\Common Files\NSV
2009-09-23 00:01 . 2009-06-07 18:33 -------- d-----w- c:\program files\SWiSH Max2
2009-09-16 12:12 . 2009-01-26 12:15 -------- d-----w- c:\program files\Windows Live
2009-09-16 12:10 . 2009-01-26 12:11 -------- d-----w- c:\program files\MSN Messenger
2009-09-09 17:50 . 2007-12-30 16:44 -------- d-----w- c:\documents and settings\XPPRESP3\Application Data\First dog deaf
2009-09-09 17:45 . 2008-05-13 11:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Part Hide Grey Pop
2009-09-06 03:48 . 2009-09-06 03:48 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-29 00:10 . 2009-08-29 00:10 -------- d-----w- c:\program files\MSBuild
2009-08-29 00:10 . 2009-08-29 00:10 -------- d-----w- c:\program files\Reference Assemblies
2009-08-14 03:58 . 2009-10-09 14:03 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-08-05 09:11 . 2004-08-04 09:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-26 13:44 . 2009-07-26 13:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-23 21:42 . 2009-07-23 21:42 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-07-23 21:42 . 2009-07-23 21:42 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-07-23 21:42 . 2005-03-11 15:28 44944 -c----w- c:\windows\system32\drivers\PxHelp20.sys
2009-07-17 18:55 . 2004-08-04 09:56 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 07:08 . 2005-08-15 15:18 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2008-07-02 18:36 . 2008-12-12 00:13 67696 -c--a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-07-02 18:36 . 2008-12-12 00:13 54376 -c--a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-07-02 18:36 . 2008-12-12 00:13 34952 -c--a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-07-02 18:36 . 2008-12-12 00:13 46720 -c--a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-07-02 18:36 . 2008-12-12 00:13 172144 -c--a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2008-01-13 02:30 . 2008-01-13 02:30 88 -csh--r- c:\windows\system32\0440AACFB9.sys
2008-01-13 02:30 . 2008-01-13 02:30 952 -csha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-05 20:43 . 2009-06-04 15:38 98644000 --sha-w- c:\windows\system32\drivers\fidbox.dat
.
------- Sigcheck -------
[7] 2001-08-23 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\beep.sys
[-] 2009-06-05 . D6252082BD78DFFFA5F15EFC63D18A81 . 26112 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
[-] 2009-06-04 . 1FD6849973F52DA996D17F766EA9B4DC . 24576 . . [5.1.2600.2180] . . c:\windows\system32\userinit.exe
[-] 2009-06-09 . 1C551E077E62B7ADDB6F4E6D79ACC774 . 1033216 . . [6.00.2900.3156] . . c:\windows\explorer.exe
[-] 2009-06-05 . D0806AED134EA4E93321789A2437CC1E . 1033728 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
[-] 2009-06-05 . F6958F4071D403BF66BCAABC6470A23F . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
[-] 2009-06-05 . CBFD4A7CA28248CA7DDA514B59FD2C31 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\wscntfy.exe
[-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\sfcfiles.dll
[-] 2005-12-19 . 784DDC1F40C4F729284D5A73930F0C9D . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
[-] 2008-04-14 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\regsvc.dll
c:\windows\system32\drivers\beep.sys ... is missing !!
c:\windows\system32\wscntfy.exe ... is missing !!
c:\windows\system32\regsvc.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-11-09 938496]
"Google Update"="c:\documents and settings\XPPRESP3\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-09 133104]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-09 68856]
"Octoshape Streaming Services"="c:\documents and settings\XPPRESP3\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]
"Dumb Meet"="c:\docume~1\XPPRESP3\APPLIC~1\FIRSTD~1\cdrom bold option.exe" [2009-09-09 536576]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2009-06-30 2836376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-06-04 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-01 148888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-14 198160]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-07-22 1181064]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2009-06-04 44544]
c:\documents and settings\XPPRESP3\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"RestrictRun"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Canon LBP-810-Statusfenster.LNK]
backup=c:\windows\pss\Canon LBP-810-Statusfenster.LNKCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Media Key.lnk]
backup=c:\windows\pss\Media Key.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
backup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Orbit.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
backup=c:\windows\pss\PalTalk.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"="0"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"c:\\Program Files\\Online TV Player 4\\TVPlayer.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\XPPRESP3\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\XPPRESP3\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\XPPRESP3\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*

isabled

xpsp2res.dll,-22009
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [09/10/2009 05:03 م 206256]
R1 kbfilter;Keyboard Filter Driver;c:\windows\system32\drivers\kbfilter.sys [27/01/2009 06:45 م 12856]
R1 UsbFltr;WayTechUSBFilterDriver;c:\windows\system32\drivers\UsbFltr.sys [27/01/2009 06:45 م 8576]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [16/09/2009 03:12 م 54752]
R2 RapidPort;RapidPort;c:\windows\system32\drivers\CAPLPTN.SYS [23/12/2008 06:29 م 22912]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [09/10/2009 05:03 م 348824]
R2 WebUpdate4;Web Update Wizard Service V4;c:\windows\system32\WebUpdateSvc4.exe [15/10/2007 06:32 م 237784]
S2 gupdate1c9bc22c4939acc;خدمة تحديث Google (gupdate1c9bc22c4939acc);c:\program files\Google\Update\GoogleUpdate.exe [13/04/2009 01:29 م 133104]
S3 fsssvc;خدمة أمان العائلة في Windows Live;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 10:48 م 704864]
S3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [07/08/2003 04:42 م 6528]
S3 GNDHVF;Genius VideoCAM Smart300 V2;c:\windows\system32\drivers\gndhvf.sys [16/02/2008 06:53 م 225152]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
NETSVCS REQUIRES REPAIRS - current entries shown
6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
ERSvc
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Netman
Nla
NWCWorkstation
Nwsapagent
Rasauto
Rasman
Remoteaccess
Schedule
Seclogon
SENS
Sharedaccess
SRService
Tapisrv
Themes
TrkWks
WZCSVC
Wmi
WmdmPmSp
winmgmt
xmlprov
BITS
ShellHWDetection
WmdmPmSN
wuauserv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
.
Contents of the 'Scheduled Tasks' folder
2009-10-09 c:\windows\Tasks\A4D1F67991D26779.job
- c:\docume~1\xppresp3\applic~1\firstd~1\FlawKnobSurf.exe [2009-07-13 17:50]
2009-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 10:29]
2009-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 10:29]
2009-09-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-602162358-343818398-682003330-1001Core.job
- c:\documents and settings\XPPRESP3\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-27 20:11]
2009-10-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-602162358-343818398-682003330-1001UA.job
- c:\documents and settings\XPPRESP3\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-27 20:11]
2009-07-10 c:\windows\Tasks\Schedule Task Weekly.job
- c:\program files\Registry Easy\RE.exe [2009-06-05 20:38]
2009-10-09 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2007-07-13 15:43]
2009-10-07 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2007-07-13 15:43]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyOverride = local
IE: Compare Prices with &Dealio - c:\documents and settings\XPPRESP3\Application Data\Dealio\kb127\res\DealioSearch.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java -
FF - ProfilePath - c:\documents and settings\XPPRESP3\Application Data\Mozilla\Firefox\Profiles\5tuv9daf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\documents and settings\XPPRESP3\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1500000
FF - user.js: content.notify.interval - 750000
FF - user.js: nglayout.initialpaint.delay - 100
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
txtfile=NOTEPAD %1
vbefile\shell\edit\command=c:\windows\Notepad.exe %1
vbsfile\shell\edit\command=c:\windows\Notepad.exe %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-10-09 19:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0c063e16-9741-4916-bcef-3dcb0f45c4da}]
@Denied: (Full) (Everyone)
"Model"=dword:00000067
"Therad"=dword:0000002a
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):c2,d7,24,82,45,3b,c3,3e,6f,82,14,ae,44,c2,42,c6,4f,4e,7b,4a,f1,
86,87,ed,b8,a4,0b,e8,48,bd,52,c4,e6,a7,ac,ff,eb,73,7f,ea,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):6d,15,1f,5e,1d,74,b8,e4,26,88,b9,eb,0d,3f,e0,16,d3,fb,c4,11,f5,
90,5c,0c,38,96,4c,1f,df,17,19,dd,ed,e5,d3,4a,8a,8e,62,77,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{a5746d5f-59dd-4cc9-9c65-a6188d5c643f}]
@Denied: (Full) (Everyone)
"Model"=dword:00000062
"Therad"=dword:00000001
"MData"=hex(0):cb,9b,ad,ef,27,7d,29,69,f5,02,f0,76,aa,4a,f1,7c,d3,d9,67,7f,6a,
4b,7b,ad,04,7a,b1,b5,76,9b,27,47,ab,81,70,e5,ff,6d,c8,6d,13,34,d4,ec,91,6f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F90BA618-B174-5930-86F7-BD23749F1E4C}\InProcServer32*]
"kajngccjabphghdbhecjeg"=hex:62,61,6a,67,00,8e
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(464)
c:\windows\system32\GTGina.dll
- - - - - - - > 'explorer.exe'(3220)
c:\windows\system32\WININET.dll
c:\program files\Spyware Doctor\pctgmhk.dll
c:\windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Crypserv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PSIService.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\WdfMgr.exe
c:\windows\system32\CAPRPCSK.EXE
c:\windows\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
c:\windows\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2009-10-09 19:31 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-09 16:30
Pre-Run: 14,267,744,256 bytes free
Post-Run: 14,273,114,112 bytes free
616 --- E O F --- 2009-10-03 00:01