ComboFix 08-12-07.04 - أبو رغـــد 12/09/2008 22:19:46.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.971 [GMT 3:00]
Running from: c:\documents and settings\أبو رغـــد.RG-001\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\system32\404Fix.exe
c:\windows\system32\Cache
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
D:\resycled
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Legacy_IPRIP
-------\Service_asc3360pr
-------\Service_Iprip
-------\Legacy_ASC3360PR
-------\Legacy_IPRIP
-------\Service_asc3360pr
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2008-11-09 to 2008-12-09 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-09 19:25 --------- d---a-w c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2008-12-09 19:13 --------- d-----w c:\program files\Softwin
2008-12-09 18:22 9,170,976 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-09 18:22 109,592 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-09 17:54 --------- d-----w c:\program files\PowerArchiver
2008-12-09 17:32 131,072 ----a-w c:\windows\system32\igfxtray.exe
2008-12-09 17:05 --------- d-----w c:\program files\Windows Defender
2008-12-09 17:02 --------- d-----w c:\program files\Paltalk Messenger
2008-12-09 17:02 --------- d-----w c:\program files\Orbitdownloader
2008-12-09 17:02 --------- d-----w c:\program files\MyPal
2008-12-09 17:02 --------- d-----w c:\program files\Modem Helper
2008-12-09 17:02 --------- d-----w c:\program files\Mobily Connect Card
2008-12-09 16:59 --------- d-----w c:\program files\ManyCam 2.3
2008-12-09 16:57 --------- d-----w c:\program files\Internet Audio Mix
2008-12-09 16:57 --------- d-----w c:\program files\GVR
2008-12-09 16:41 --------- d-----w c:\program files\Trend Micro
2008-12-09 16:40 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Trend Micro
2008-12-09 16:26 50,192 ----a-w c:\windows\system32\drivers\tmactmon.sys
2008-12-09 16:26 49,680 ----a-w c:\windows\system32\drivers\tmevtmgr.sys
2008-12-09 16:26 144,912 ----a-w c:\windows\system32\drivers\tmcomm.sys
2008-12-09 16:16 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2008-12-09 16:04 --------- d-----w c:\documents and settings\أبو رغـــد.RG-001\Application Data\Orbit
2008-12-09 14:44 --------- d-----w c:\program files\Spyware Doctor
2008-12-09 14:24 --------- d-----w c:\documents and settings\أبو رغـــد.RG-001\Application Data\PC Tools
2008-12-09 13:49 81,984 ----a-w c:\windows\system32\bdod.bin
2008-12-09 13:11 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\BitDefender
2008-12-09 13:10 --------- d-----w c:\program files\Common Files\BitDefender
2008-12-07 20:46 49,152 ----a-w c:\windows\system32\ico.exe
2008-12-07 20:42 --------- d-----w c:\program files\Windows Live Safety Center
2008-12-07 20:40 --------- d-----w c:\program files\SUPERAntiSpyware
2008-12-07 20:39 --------- d-----w c:\program files\Messenger Plus! Live
2008-12-07 20:39 --------- d-----w c:\program files\ma-config.com
2008-12-07 20:38 --------- d-----w c:\program files\Common Files\PCCamera
2008-12-07 09:20 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-06 13:28 --------- d-----w c:\documents and settings\أبو رغـــد.RG-001\Application Data\Bitdefender
2008-12-06 13:27 --------- d-----w c:\program files\BitDefender
2008-12-04 22:36 --------- d-----w c:\program files\Broadcom
2008-12-04 21:49 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-12-04 21:49 --------- d-----w c:\documents and settings\أبو رغـــد.RG-001\Application Data\SUPERAntiSpyware.com
2008-12-04 21:48 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-04 14:00 --------- d-----w c:\documents and settings\LocalService.NT AUTHORITY\Application Data\PeerNetworking
2008-12-03 19:49 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2008-12-03 19:17 --------- d-----w c:\program files\BrOnZ Patch Pro
2008-12-02 05:00 --------- d-----w c:\documents and settings\أبو رغـــد.RG-001\Application Data\ESET
2008-12-01 22:32 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\ESET
2008-11-29 19:53 --------- d-----w c:\program files\TuneUp Utilities 2008
2008-11-24 20:58 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Creative
2008-11-24 19:06 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2008-11-24 05:15 --------- d-----w c:\program files\Nokia
2008-11-23 21:04 --------- d-----w c:\program files\MSXML 4.0
2008-11-23 09:34 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2008-11-23 09:34 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2008-11-23 08:44 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Nokia
2008-11-23 08:37 --------- d-----w c:\program files\MSXML 6.0
2008-11-23 08:31 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Installations
2008-11-21 19:51 355,584 ----a-w c:\windows\system32\TuneUpDefragService.exe
2008-11-21 03:19 410,976 ----a-w c:\windows\system32\deploytk.dll
2008-11-21 03:19 --------- d-----w c:\program files\Java
2008-11-18 18:59 --------- d-----w c:\program files\BandRich
2008-11-17 10:47 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Messenger Plus!
2008-11-17 10:32 --------- d-----w c:\program files\Creative
2008-11-13 23:31 --------- d-----w c:\program files\SigmaTel
2008-11-10 19:17 --------- d-----w c:\program files\CCleaner
2008-11-09 13:10 --------- d-----w c:\documents and settings\أبو رغـــد.RG-001\Application Data\Paltalk
2008-11-07 03:21 --------- d-----w c:\program files\FunText
2008-11-07 03:20 --------- d-----w c:\program files\Real
2008-11-06 14:13 --------- d-----w c:\program files\Windows Live
2008-11-06 14:03 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\WLInstaller
2008-11-06 08:54 56,360 ----a-w c:\windows\system32\WBHELP2.DLL
2008-11-06 04:50 --------- d-----w c:\program files\Avant Browser
2008-11-04 17:27 --------- d-----w c:\program files\Magix
2008-11-01 22:22 --------- d-----w c:\program files\TWiZA
2008-11-01 20:04 --------- d-----w c:\program files\Google
2008-10-31 21:31 --------- d-----w c:\program files\EPSON
2008-10-31 21:30 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\EPSON
2008-10-30 21:15 --------- d-----w c:\program files\NOS
2008-10-30 21:15 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\NOS
2008-10-30 20:12 --------- d-----w c:\documents and settings\أبو رغـــد.RG-001\Application Data\Avant Profiles
2008-10-30 19:47 --------- d-----w c:\program files\Dell
2008-10-30 19:27 --------- d-----w c:\program files\Intel
2008-10-30 18:15 376,832 ----a-w c:\windows\system32\AEGISI5INSTALLER.EXE
2008-10-30 17:04 --------- d-----w c:\documents and settings\أبو رغـــد.RG-001\Application Data\inSpeak
2008-10-30 17:03 --------- d-----w c:\program files\inSpeak
2008-10-30 17:03 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\inSpeak
2008-10-30 16:43 203,776 ----a-w c:\windows\system32\clrviddc.dll
2008-10-30 16:30 --------- d-----w c:\program files\Common Files\xing shared
2008-10-30 16:30 --------- d-----w c:\program files\Common Files\Real
2008-10-30 16:19 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\TuneUp Software
2008-10-30 16:19 --------- d-----w c:\documents and settings\أبو رغـــد.RG-001\Application Data\TuneUp Software
2008-10-30 11:56 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2008-10-30 11:24 --------- d-----w c:\program files\MSBuild
2008-10-30 10:48 --------- d-----w c:\program files\Microsoft Works
2008-10-30 10:36 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\ma-config.com
2008-10-30 10:32 --------- d-----w c:\documents and settings\أبو رغـــد.RG-001\Application Data\GrabPro
2008-10-30 10:18 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\ConeXware
2008-10-30 10:05 --------- d-----w c:\program files\Reference Assemblies
2008-10-30 08:10 --------- d-----w c:\documents and settings\أبو رغـــد.RG-001\Application Data\InstallShield
2008-10-30 07:40 --------- d-----w c:\program files\WIDCOMM
2008-10-16 11:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 11:06 208,744 ----a-w c:\windows\system32\muweb.dll
.
------- Sigcheck -------
04/15/2008 03:00 PM 14336 6b1139ca38db1678487678c44874b80f c:\windows\system32\svchost.exe
04/15/2008 03:00 PM 14336 6b1139ca38db1678487678c44874b80f c:\windows\system32\dllcache\svchost.exe
04/15/2008 03:00 PM 578048 f95655e872967ae2cd4c19d8914babb7 c:\windows\system32\user32.dll
04/15/2008 03:00 PM 578048 f95655e872967ae2cd4c19d8914babb7 c:\windows\system32\dllcache\user32.dll
04/15/2008 03:00 PM 82432 8a2b77e2a2f2ad328ee3a2ed91f08ebb c:\windows\system32\ws2_32.dll
04/15/2008 03:00 PM 82432 8a2b77e2a2f2ad328ee3a2ed91f08ebb c:\windows\system32\dllcache\ws2_32.dll
06/23/2008 06:38 PM 827904 bd4be2824bc805da1f29385519b865f9 c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
08/20/2008 08:06 AM 665088 02b59535250fd4f4a2d2ab005a35bae5 c:\windows\$hf_mig$\KB956390\SP3QFE\wininet.dll
08/26/2008 12:08 PM 827904 bceb6d8a6bea74628db977215081652a c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
08/20/2008 08:10 AM 664576 b67627f9fe98061a23d0ae3f16cd7c9b c:\windows\ie7\wininet.dll
08/13/2007 06:54 PM 818688 a4a0fc92358f39538a6494c42ef99fe9 c:\windows\ie7updates\KB953838-IE7\wininet.dll
06/23/2008 07:15 PM 826368 3f4bca25f29394995161e8e85d925c1a c:\windows\ie7updates\KB956390-IE7\wininet.dll
04/15/2008 03:00 PM 664576 699b4dbfba7d4201d67c521e5df0670d c:\windows\system32\wininet.dll
04/15/2008 03:00 PM 664576 699b4dbfba7d4201d67c521e5df0670d c:\windows\system32\dllcache\wininet.dll
04/15/2008 03:00 PM 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\system32\dllcache\tcpip.sys
04/15/2008 03:00 PM 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\system32\drivers\tcpip.sys
04/15/2008 03:00 PM 506880 bcedf9dccbc807108ce34c9834074c34 c:\windows\system32\winlogon.exe
04/15/2008 03:00 PM 506880 bcedf9dccbc807108ce34c9834074c34 c:\windows\system32\dllcache\winlogon.exe
04/15/2008 03:00 PM 182656 1df7f42665c94b825322fae71721130d c:\windows\system32\dllcache\ndis.sys
04/15/2008 03:00 PM 182656 1df7f42665c94b825322fae71721130d c:\windows\system32\drivers\ndis.sys
04/15/2008 03:00 PM 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\system32\dllcache\ip6fw.sys
04/15/2008 03:00 PM 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\system32\drivers\ip6fw.sys
08/14/2008 07:24 PM 2067584 5be9c85582d409f6b0520f671b7c4ea7 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
04/15/2008 03:00 PM 2025472 732887e7fdc05bed5a79a5ec49fd7e8d c:\windows\system32\ntkrnlpa.exe
08/14/2008 07:24 PM 2190720 8d99acb2cd1a686e7a98cc22119de324 c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
04/15/2008 03:00 PM 2146816 1d8896827aaf26d44f6fea9498f296cf c:\windows\system32\ntoskrnl.exe
04/15/2008 03:00 PM 1031168 ca3445dce9eb70a2ca2504e0af5c543f c:\windows\explorer.exe
04/15/2008 03:00 PM 1031168 ca3445dce9eb70a2ca2504e0af5c543f c:\windows\system32\dllcache\explorer.exe
04/15/2008 03:00 PM 108544 940b71d9046a5356e9b5a3cd5a75b064 c:\windows\system32\services.exe
04/15/2008 03:00 PM 108544 940b71d9046a5356e9b5a3cd5a75b064 c:\windows\system32\dllcache\services.exe
04/15/2008 03:00 PM 13312 99ae1390a271b02d752178df9e8442a3 c:\windows\system32\lsass.exe
04/15/2008 03:00 PM 13312 99ae1390a271b02d752178df9e8442a3 c:\windows\system32\dllcache\lsass.exe
04/15/2008 03:00 PM 15360 252f972131eb23596c20b82ca190dc5c c:\windows\system32\ctfmon.exe
04/15/2008 03:00 PM 15360 252f972131eb23596c20b82ca190dc5c c:\windows\system32\dllcache\ctfmon.exe
04/15/2008 03:00 PM 57856 42eca7ea7d2e8b874bb9e4d147a5f783 c:\windows\system32\spoolsv.exe
04/15/2008 03:00 PM 57856 42eca7ea7d2e8b874bb9e4d147a5f783 c:\windows\system32\dllcache\spoolsv.exe
04/15/2008 12:00 PM 110592 9498cf0d334b282aa58d1dfc370738de c:\windows\system32\wuauclt.exe
10/16/2008 02:09 PM 51224 e654b78d2f1d791b30d0ed9a8195ec22 c:\windows\system32\dllcache\wuauclt.exe
04/15/2008 03:00 PM 26112 b2b4e4722caafe109bec13773bcb75b0 c:\windows\system32\userinit.exe
04/15/2008 03:00 PM 26112 b2b4e4722caafe109bec13773bcb75b0 c:\windows\system32\dllcache\userinit.exe
04/15/2008 12:00 PM 295424 58e202572d3251bf2687bf841ea00ce0 c:\windows\system32\termsrv.dll
04/15/2008 12:00 PM 295424 58e202572d3251bf2687bf841ea00ce0 c:\windows\system32\dllcache\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [12/09/2008 08:05 PM 5714944]
"ManyCam"="c:\program files\ManyCam 2.3\ManyCam.exe" [12/09/2008 07:59 PM 1720320]
"HUAWEI 3G Data Card MTS"="c:\progra~1\MOBILY~1\Mobily Connect Card.exe" [12/09/2008 08:02 PM 335872]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/15/2008 03:00 PM 15360]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [12/09/2008 07:26 PM 570736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [12/09/2008 07:55 PM 180224]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [12/07/2008 11:39 PM 24064]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [12/19/2005 09:08 AM 1429504]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [12/09/2008 07:50 PM 270336]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [12/09/2008 08:04 PM 761856]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [12/09/2008 07:26 PM 1048632]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [08/25/2008 11:36 AM 1168264]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/15/2008 03:00 PM 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [12/09/2008 07:52 PM 29184]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [12/09/2008 07:26 PM 570736]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 0 (0x0)
"EnableLUA"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [05/13/2008 09:13 AM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
07/23/2008 03:28 PM 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.speex32"= speex32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"ekrn"=2 (0x2)
"EhttpSrv"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CreativeTaskScheduler"="c:\program files\Creative\Shared Files\CTSched.exe" /logon
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= c:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\inSpeak\\inSpeak.exe"=
"d:\\paltalk\\paltalk.exe"=
"c:\\Program Files\\Mobily Connect Card\\Mobily Connect Card.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"c:\\WINDOWS\\system32\\userinit.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\WINDOWS\\system32\\WLTRAY.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\WINDOWS\\system32\\ICO.EXE"=
"c:\\PROGRA~1\\MOBILY~1\\Mobily Connect Card.exe"=
"c:\\Program Files\\ManyCam 2.3\\ManyCam.exe"=
"c:\\Documents and Settings\\All Users.WINDOWS\\Application Data\\EPSON\\EPW!3 SSRP\\E_S30RP1.EXE"=
"c:\\WINDOWS\\System32\\bcmwltry.exe"=
"c:\\Program Files\\BitDefender\\BitDefender 2008\\bdagent.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
"c:\\WINDOWS\\system32\\MsiExec.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP

xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP

xpsp2res.dll,-22016
"500:UDP"= 500:UDP

xpsp2res.dll,-22017
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP

eer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-11-17 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-11-17 55024]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-12-09 356920]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
S1 is-EE6TMdrv;is-EE6TMdrv;c:\windows\system32\drivers\85698667.sys []
S2 is-EE6TM;is-EE6TM;"c:\documents and settings\All Users.WINDOWS\سطح المكتب\Kaspersky Lab Tool\is-EE6TM\is-EE6TM.exe" -r [2008-12-09 290816]
S2 WinDefend;Windows Defender;"c:\program files\Windows Defender\MsMpEng.exe" [2006-11-03 13592]
S3 BandLuxe_Service;BandLuxe Service;"c:\program files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe" -e []
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\DRIVERS\br3gmdm.sys [2008-11-18 100096]
S3 maconfservice;Ma-Config Service;"c:\program files\ma-config.com\maconfservice.exe" []
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2008-11-23 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2008-11-23 8320]
S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-11-17 7408]
S3 V0330VID;WebCam Vista/Live! Cam Chat;c:\windows\system32\DRIVERS\V0330Vid.sys [2008-11-17 157696]
S4 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-10-31 33752]
S4 setup_7.0.0.180_13.03.2008_17-22;setup_7.0.0.180_13.03.2008_17-22;"c:\documents and settings\All Users.WINDOWS\سطح المكتب\Kaspersky Lab Tool\setup_7.0.0.180_13.03.2008_17-22.exe" -r []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{232c9810-6cad-11dd-aff2-0015c5b89270}]
\Shell\AutoRun\command - G:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a7b69b7a-6c75-11dd-aff1-0015c5b89270}]
\Shell\AutoRun\command - G:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a7b69b7e-6c75-11dd-aff1-0015c5b89270}]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b47e5c4f-b862-11dd-a474-0016cfd7d074}]
\Shell\AutoRun\command - F:\AutoRun.exe
*Newly Created Service* - ASC3360PR
.
s of the 'Scheduled Tasks' folder
2008-11-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [06/20/2008 09:09 AM]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-HiChatter - c:\program files\HiChatter Messenger\HiChater.exe
HKCU-Run-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
HKLM-Run-Dell QuickSet - c:\program files\Dell\QuickSet\quickset.exe
HKLM-Run-SigmatelSysTrayApp - c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-09 22:25:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(672)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\System32\BCMLogon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\scardsvr.exe
c:\windows\system32\msdtc.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\documents and settings\All Users.WINDOWS\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\netdde.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
c:\windows\system32\locator.exe
c:\windows\system32\rsvp.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\system32\snmp.exe
c:\windows\system32\tlntsvr.exe
c:\windows\system32\TuneUpDefragService.exe
c:\windows\system32\vssvc.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\mqsvc.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\inetsrv\davcdata.exe
.
**************************************************************************
.
Completion time: 12/09/2008 22:28:10 - machine was rebooted [أبو رغـــد]
ComboFix-quarantined-files.txt 2008-12-09 19:28:06
Pre-Run: 4,791,459,840 bytes free
Post-Run: 4,736,172,032 bytes free
366 --- E O F --- 2008-12-03 18:52:19
عقب الموت اشتغلت معي