ComboFix 08-05-11.1 - help 05/12/2008 13:56:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.202 [GMT 3:00]
Running from: C:\Documents and Settings\help\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\help\Application Data\macromedia\Flash Player\#Shareds\Q4JPXHPP\iforex.com
C:\Documents and Settings\help\Application Data\macromedia\Flash Player\#Shareds\Q4JPXHPP\iforex.com\Emerp\Events\flash_.swf\user_data.sol
C:\Documents and Settings\help\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\help\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\WINDOWS\mywinsys.ini
C:\WINDOWS\system32\Desktop_.ini
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\Packet.dll
C:\WINDOWS\system32\WanPacket.dll
C:\WINDOWS\system32\winitn.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-04-12 to 2008-05-12 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-12 11:01 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-05-12 11:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-12 10:59 3,188 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-12 10:59 186,400 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-12 05:27 --------- d-----w C:\Program Files\Samy Soft
2008-05-12 03:31 --------- d--h--w C:\Program Files\Bifrost
2008-05-11 23:43 --------- d-----w C:\Documents and Settings\help\Application Data\cleaner
2008-05-11 22:25 --------- d-----w C:\Documents and Settings\help\Application Data\chirpscreen
2008-05-11 22:02 --------- d-----w C:\Program Files\ManyCam 2.2
2008-05-07 19:35 --------- d-----w C:\Documents and Settings\help\Application Data\U3
2008-05-07 09:25 --------- d-----w C:\Program Files\Google
2008-05-06 20:38 --------- d-----w C:\Program Files\Common Files\xing shared
2008-05-06 20:38 --------- d-----w C:\Program Files\Common Files\Real
2008-05-06 16:14 --------- d-----w C:\Documents and Settings\help\Application Data\DMCache
2008-05-05 16:51 --------- d-----w C:\Documents and Settings\help\Application Data\Acoustica
2008-05-05 16:50 --------- d-----w C:\Program Files\Acoustica Shared Effects
2008-05-05 16:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Acoustica
2008-05-03 20:38 --------- d-----w C:\Documents and Settings\help\Application Data\Thinstall
2008-05-02 01:24 --------- d-----w C:\Program Files\Goomsoft
2008-05-01 15:27 --------- d-----w C:\Program Files\3D Real Boxshot
2008-04-28 19:44 --------- d-----w C:\Documents and Settings\help\Application Data\Ulead Systems
2008-04-28 18:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-04-28 18:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-28 18:46 --------- d-----w C:\Program Files\Common Files\InterVideo
2008-04-28 18:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\InterVideo
2008-04-28 18:45 --------- d-----w C:\Program Files\Windows Media Components
2008-04-28 18:45 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2008-04-28 18:44 --------- d-----w C:\Program Files\Ulead Systems
2008-04-24 20:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\GrabJPG
2008-04-24 08:24 --------- d-----w C:\Program Files\SWiSHmax
2008-04-23 13:27 --------- d-----w C:\Program Files\Paltalk Messenger
2008-04-21 21:29 --------- d-----w C:\Program Files\AskPBar
2008-04-17 21:06 --------- d-----w C:\Program Files\Uconomix
2008-04-17 16:21 --------- d-----w C:\Program Files\Video Convert Master
2008-04-13 18:35 --------- d-----w C:\Program Files\CEDP Stealer 6.0 for Messenger
2008-04-12 19:41 --------- d-----w C:\Program Files\مشغل الفلاش العربي
2008-04-11 11:26 --------- d-----w C:\Program Files\Video GIF Converter
2008-04-11 11:21 --------- d-----w C:\Program Files\VS Revo Group
2008-04-10 23:41 --------- d-----w C:\Documents and Settings\help\Application Data\CyberScrub
2008-04-10 01:48 --------- d-----w C:\Program Files\Batch Image Resizer
2008-04-08 21:23 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-08 21:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-08 19:36 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-04-08 19:35 --------- d-----w C:\Documents and Settings\help\Application Data\TuneUp Software
2008-04-08 19:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-04-07 18:10 --------- d-----w C:\Program Files\Easy GIF Animator
2008-04-07 13:22 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-06 17:43 --------- d-----w C:\Program Files\Ozone
2008-04-03 21:56 --------- d-----w C:\Program Files\Sound Pilot
2008-03-28 15:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\TechSmith
2008-03-26 19:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Webcammax
2008-03-25 14:33 --------- d-----w C:\Program Files\WebcamMax
2008-03-25 14:30 --------- d-----w C:\Documents and Settings\help\Application Data\Webcammax
2008-03-18 21:09 --------- d-----w C:\Program Files\ShiningMorning
2008-03-18 14:22 --------- d-----w C:\Program Files\Enigma Software Group
2008-03-15 21:53 --------- d-----w C:\Program Files\Browster
2008-03-14 22:25 --------- d-----w C:\Documents and Settings\help\Application Data\MSN Pictures Displayer
2008-03-14 19:01 --------- d-----w C:\Program Files\MSN Pictures Displayer
2008-03-14 00:29 --------- d-----w C:\Documents and Settings\help\Application Data\GozTun
2008-03-13 10:03 --------- d-----w C:\Program Files\U-Broadcast
2008-03-13 02:51 --------- d-----w C:\Documents and Settings\help\Application Data\Recordpad
2008-03-13 02:51 --------- d-----w C:\Documents and Settings\help\Application Data\NCH Swift Sound
2008-03-13 02:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-03-13 02:50 --------- d-----w C:\Program Files\NCH Software
2008-03-12 22:57 81,920 ----a-w C:\Documents and Settings\help\Application Data\ezpinst.exe
2008-03-12 22:57 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-03-12 22:57 47,360 ----a-w C:\Documents and Settings\help\Application Data\pcouffin.sys
2008-03-12 22:57 --------- d-----w C:\Documents and Settings\help\Application Data\Vso
2008-03-12 18:23 --------- d-----w C:\Program Files\SplitCam
2008-03-12 16:44 13,824 ----a-w C:\WINDOWS\system32\drivers\splitcam.sys
2008-03-12 16:24 --------- d-----w C:\Program Files\Luminositi
2008-01-14 17:54 952 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [09/03/2005 03:18 PM 94208]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [03/21/2008 12:56 AM 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [07/25/2007 04:44 AM 8433664]
"nwiz"="nwiz.exe" [07/25/2007 04:45 AM 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [07/25/2007 04:44 AM 81920]
"RTHDCPL"="RTHDCPL.EXE" [07/25/2007 04:43 AM 16342528 C:\WINDOWS\RTHDCPL.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [07/25/2007 04:42 AM 827392]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [07/25/2007 04:43 AM 159744]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [07/25/2007 04:41 AM 752136]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [09/01/2006 03:57 PM 282624]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [04/08/2005 03:52 PM 48752]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [04/17/2005 12:30 PM 85184]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 11:50 AM 155648]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 12:56 AM 110592 C:\WINDOWS\system32\bthprops.cpl]
"WebcamMaxMoniter"="C:\Program Files\WebcamMax\wcmmon.exe" [09/16/2007 08:15 AM 450048]
"UVS11 Preload"="C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe" [03/03/2007 02:12 PM 341488]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05/06/2008 11:37 PM 185896]
"AVP"="C:\Documents and Settings\All Users\سطح المكتب\Kaspersky Lab Tool\setup_7.0.0.180_12.05.2008_10-33[1].exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"MSVideo"= CSvidcap.dll
"vidc.sccd"= C:\PROGRA~1\LUMINO~1\SoftCam1.5\Driver\SCCodec.dll
"MSVideo7"= C:\PROGRA~1\LUMINO~1\SoftCam1.5\Driver\SCVid32.dll
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^SnagIt 8.lnk]
path=C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\SnagIt 8.lnk
backup=C:\WINDOWS\pss\SnagIt 8.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 03/21/2008 12:56 AM 5724184 C:\Program Files\Windows Live\Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recordpad]
C:\Program Files\NCH Swift Sound\Recordpad\recordpad.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter Security Suite]
--a------ 01/23/2008 02:47 PM 847872 C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Mobily Connect Card\\Mobily Connect Card.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
R2 CamthWDM;WebcamMax, WDM Video Capture;C:\WINDOWS\system32\DRIVERS\CamthWDM.sys [10/06/2007 11:38 AM]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [08/04/2004 12:56 AM]
R3 Cam5607;Acer Crystal Eye webcam;C:\WINDOWS\system32\Drivers\BisonC07.sys [05/03/2007 11:29 AM]
R3 EraserUtilDrv10741;EraserUtilDrv10741;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10741.sys [01/22/2008 12:00 PM]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\WINDOWS\system32\DRIVERS\ManyCam.sys [01/14/2008 01:06 PM]
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys [07/25/2007 04:45 AM]
S3 mcdevice;mcdevice;C:\WINDOWS\system32\DRIVERS\mcdevice.sys [12/05/2007 11:45 PM]
S3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [12/16/2006 11:37 PM]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [04/08/2008 10:35 PM]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{35b49085-c3d4-11dc-aae5-001b3861815d}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{00C5E2B7-7395-18DE-A801-1AE869CD3209}]
C:\Program Files\Bifrost\hp877.exe s
.
s of the 'Scheduled Tasks' folder
"2008-05-12 11:00:51 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-05-12 14:01:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Documents and Settings\help\Local Settings\Application Data\Ahead\Nero Home\indexstore.db-journal 512 bytes
scan completed successfully
hidden files: 1
**************************************************************************
"ImagePath"="\"C:\Documents and Settings\All Users\سطح المكتب\Kaspersky Lab Tool\setup_7.0.0.180_12.05.2008_10-33
[1].exe\" -r"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\setup_7.0.0.180_12.05.2008_10-33[1]]
"ImagePath"="\"C:\Documents and Settings\All Users\سطح المكتب\Kaspersky Lab Tool\setup_7.0.0.180_12.05.2008_10-33
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\Apoint2K\ApntEx.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe
C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
C:\Program Files\TechSmith\SnagIt 8\TscHelp.exe
C:\Program Files\TechSmith\SnagIt 8\SnagPriv.exe
C:\DOCUME~1\help\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Completion time: 05/12/2008 14:04:58 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-12 11:04:53
Pre-Run: 22,535,577,600 bytes free
Post-Run: 22,654,799,872 bytes free
233