ComboFix 08-11-19.08 - حمودة 11/20/2008 22:20:06.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1256.1.1033.18.295 [GMT 3:00]
Running from: c:\users\حمودة\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-20 to 2008-11-20 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-20 19:24 454,324,256 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-20 09:59 --------- d-----w c:\users\حمودة\AppData\Roaming\Skype
2008-11-19 19:35 1,981,456 ----a-w c:\users\حمودة\ماجد المهندس_اطيب طعم بوستك.zip
2008-11-19 19:35 1,981,456 ----a-w c:\users\حمودة\ماجد المهندس_اطيب طعم بوستك.zip
2008-11-15 22:55 5,010,956 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-14 20:29 2,890 ----a-w c:\users\حمودة\108_01224422128.zip
2008-11-14 20:29 2,890 ----a-w c:\users\حمودة\108_01224422128.zip
2008-11-14 11:41 --------- d-----w c:\program files\Magentic
2008-11-14 11:31 596,384 ----a-w c:\users\حمودة\magentic_install.exe
2008-11-14 11:31 596,384 ----a-w c:\users\حمودة\magentic_install.exe
2008-11-13 22:33 --------- d-----w c:\programdata\Microsoft Help
2008-11-07 23:39 --------- d-----w c:\users\حمودة\AppData\Roaming\ACD Systems
2008-11-07 23:37 --------- d-----w c:\programdata\ACD Systems
2008-11-07 23:37 --------- d-----w c:\program files\Common Files\ACD Systems
2008-11-07 23:37 --------- d-----w c:\program files\ACD Systems
2008-11-07 12:19 --------- d-----w c:\program files\Common Files\Adobe
2008-11-06 10:14 --------- d-----w c:\users\حمودة\AppData\Roaming\skypePM
2008-10-13 05:20 --------- d-----w c:\programdata\Kaspersky Lab
2008-10-11 05:47 --------- d-----w c:\programdata\Dell
2008-10-04 04:02 1,506 ----a-w c:\users\حمودة\AppData\Roaming\wklnhst.dat
2008-10-02 03:49 827,392 ----a-w c:\windows\System32\wininet.dll
2008-09-29 22:40 --------- d-----w c:\program files\Internet Download Manager
2008-09-29 22:37 --------- d-----w c:\users\حمودة\AppData\Roaming\DMCache
2008-09-27 22:06 --------- d-----w c:\users\حمودة\AppData\Roaming\IDM
2008-09-27 04:32 --------- d-----w c:\program files\MSBuild
2008-09-27 04:30 --------- d-----w c:\program files\Microsoft.NET
2008-09-27 04:27 --------- d-----w c:\program files\Microsoft Visual Studio 8
2008-09-24 04:09 --------- d-----w c:\programdata\Kaspersky Lab Setup Files
2008-09-24 03:59 38,507,080 ----a-w c:\users\حمودة\kis8.0.0.454en.exe
2008-09-24 03:59 38,507,080 ----a-w c:\users\حمودة\kis8.0.0.454en.exe
2008-09-24 03:16 --------- d-----w c:\programdata\McAfee
2008-09-23 23:23 --------- d-----w c:\program files\ICQ6
2008-09-20 01:54 --------- d-----w c:\programdata\is-FMR1V
2008-09-20 01:52 26,691,480 ----a-w c:\users\حمودة\setup_7.0.0.242_20.09.2008_03-50.exe
2008-09-20 01:52 26,691,480 ----a-w c:\users\حمودة\setup_7.0.0.242_20.09.2008_03-50.exe
2008-09-18 05:09 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 02:16 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-09-10 03:40 1,334,272 ----a-w c:\windows\System32\msxml6.dll
2008-09-05 05:14 1,191,936 ----a-w c:\windows\System32\msxml3.dll
2008-08-29 01:12 174 --sha-w c:\program files\desktop.ini
2008-08-29 00:17 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-08-29 00:17 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-08-28 15:44 56 ---ha-w c:\users\All Users\ezsidmv.dat
2008-08-28 15:44 56 ---ha-w c:\programdata\ezsidmv.dat
2008-03-06 15:50 76 --sh--r c:\windows\CT4CET.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [01/19/2008 10:33 AM 1233920]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [08/13/2008 06:32 PM 206064]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"googletalk"="c:\users\حمودة\AppData\Roaming\Google\Google Talk\googletalk.exe" [01/02/2007 12:22 AM 3739648]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [01/19/2008 10:33 AM 202240]
"Magentic"="c:\progra~1\Magentic\bin\Magentic.exe" [08/04/2008 09:51 AM 488808]
"WindowsWelcomeCenter"="oobefldr.dll" [01/19/2008 10:36 AM 2153472 c:\windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [09/07/2007 09:49 AM 159744]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [08/28/2007 08:51 AM 36864]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [12/15/2007 06:54 AM 137752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [12/15/2007 06:53 AM 154136]
"Persistence"="c:\windows\system32\igfxpers.exe" [12/15/2007 06:53 AM 133656]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [07/27/2007 07:43 PM 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [03/21/2007 04:00 PM 174872]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [12/12/2007 10:03 AM 3444736]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [11/15/2007 12:24 PM 16384]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [11/01/2007 06:39 PM 189736]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [08/13/2008 06:32 PM 206064]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [11/12/2007 02:07 PM 405504]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [08/24/2007 07:00 AM 33648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [10/15/2008 01:04 AM 39792]
c:\users\¥êي§،\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-03 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-03-06 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2007-09-07 1180952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{78867C79-3068-4C73-81AC-A191CA40E69E}"= c:\program files\Dell\MediaDirect\MediaDirect.exe

ell MediaDirect
"{76900125-770C-4EE9-8100-D6CD22F7F0AD}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{C6F7D818-A29C-4D5A-BA45-75F97299BFC3}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{BFA8ED70-5F88-4234-8241-642CBF8A0BCA}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{8944BE41-E9C9-467D-B399-52B57CECF7AF}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6A2362E4-43B0-4B62-9712-006EBC51AE18}"= UDP:443

oVoo TCP المنفذ 443
"{EB24A230-6688-4815-A5F2-77D18BE204EF}"= TCP:443

oVoo UDP المنفذ 443
"{B0C1EA15-69DD-494E-BB3F-E656741168A1}"= UDP:37674

oVoo TCP المنفذ 37674
"{07368AA3-D942-46EF-9AD9-2534904A3927}"= TCP:37674

oVoo UDP المنفذ 37674
"{81B2D78A-7F31-431B-812F-112478AE0061}"= TCP:37675

oVoo UDP المنفذ 37675
"{9004A8E3-2DA5-404B-8837-B326731878C5}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{A68A2397-23EE-4AA1-B0A8-7A6CC7FCF467}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{D7DC0780-8711-4A88-823A-4D97D214FE3B}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{7825D35E-3DAC-45AC-B1BB-73DF08D1AA9D}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{3FF953A7-A23C-48C8-B6CC-F7BB1D35E38B}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A74D8A0F-7ABC-46E0-8139-B73576AD8A8F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D0F16471-CF58-4DA5-BDF2-FBF7FAE2B8FD}"= Disabled:UDP:c:\program files\Magentic\bin\MgImp.exe:Magentic
"{68A03F9B-E8C5-411E-8135-8603312EB4C6}"= Disabled:TCP:c:\program files\Magentic\bin\MgImp.exe:Magentic
"{AF39730F-41A3-4687-BC73-C89D4E87CFF6}"= Disabled:UDP:c:\users\حمودة\AppData\Local\Temp\ImInstaller\magentic_installer.exe:IncrediMail Installer
"{D5609CFF-B5D9-494A-9D83-9F3D6CF64D26}"= Disabled:TCP:c:\users\حمودة\AppData\Local\Temp\ImInstaller\magentic_installer.exe:IncrediMail Installer
"{BE9FBCFE-2270-4EC6-886F-6EEA3840DD60}"= Disabled:UDP:c:\program files\Magentic\bin\Magentic.exe:Magentic
"{D7860EDF-7A1B-43BC-B56D-2E97145C810D}"= Disabled:TCP:c:\program files\Magentic\bin\Magentic.exe:Magentic
"{A6C2C73B-6BB3-49BD-BB9F-EDC762BAC835}"= Disabled:UDP:c:\program files\Magentic\bin\Magentic.exe:Magentic
"{DD9F5A0E-9210-402F-A6F4-B595F0571433}"= Disabled:TCP:c:\program files\Magentic\bin\Magentic.exe:Magentic
"{1D30134E-FEBB-4C11-A8BB-D9059DB1F20E}"= Disabled:UDP:c:\program files\Magentic\bin\MgApp.exe:Magentic
"{0AD96397-21A3-40E3-ACE2-B46962402084}"= Disabled:TCP:c:\program files\Magentic\bin\MgApp.exe:Magentic
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 0 (0x0)
R1 is-FMR1Vdrv;is-FMR1Vdrv;c:\windows\system32\DRIVERS\77353766.sys [2008-09-20 148496]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2008-03-06 73728]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2008-03-07 111104]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\DRIVERS\OEM02Dev.sys [2008-03-07 235520]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\DRIVERS\OEM02Vfx.sys [2008-03-07 7424]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{32b7e22a-1d2d-11dd-8587-001e4ce2ed83}]
\shell\AutoRun\command - F:\vfjc8mxm.exe
\shell\explore\Command - F:\vfjc8mxm.exe
\shell\open\Command - F:\vfjc8mxm.exe
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-11-20 c:\windows\Tasks\User_Feed_Synchronization-{60EBA100-D7E0-4B5D-AD69-57E3F5D96DE8}.job
- c:\windows\system32\msfeedssync.exe [01/19/2008 10:33 AM]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{A057A204-BACC-4D26-8087-36EE87E26986} - (no file)
HKCU-Run-Device Detector - DevDetect.exe
HKLM-Run-zzz_ImInstaller_Magentic - c:\users\حمودة\AppData\Local\Temp\ImInstaller\Magentic\magentic_install.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-20 22:26:29
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 11/20/2008 22:33:18
ComboFix-quarantined-files.txt 2008-11-20 19:32:05
Pre-Run: 71,515,598,848 bytes free
Post-Run: 71,586,168,832 bytes free
163 --- E O F --- 2008-11-19 22:47:18