ComboFix 09-03-03.01 - Administrator 03/04/2009 13:45:33.4 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.502.165 [GMT 3:00]
Running from: D:\ComboFix.exe
AV: Norton Internet Security *On-access scanning enabled* (Updated)
FW: Norton AntiVirus *enabled*
FW: Norton Internet Security *enabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\dumphive.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_OREANS32
-------\Service_oreans32
((((((((((((((((((((((((( Files Created from 2009-02-04 to 2009-03-04 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-04 09:02 --------- d-----w c:\program files\Elmokadim Flash Player
2009-02-26 19:34 33,824 ----a-w c:\windows\system32\drivers\oreans32.sys
2009-02-26 10:37 --------- d-----w c:\program files\TuneUp Utilities 2009
2009-02-26 10:37 --------- d-----w c:\documents and settings\All Users\Application Data\TuneUp Software
2009-02-26 10:36 --------- d-sh--w c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-02-21 19:46 --------- d-----w c:\documents and settings\All Users\Application Data\live 64 math does
2009-02-21 19:45 --------- d-----w c:\program files\Jumpchinfast
2009-02-21 19:45 --------- d-----w c:\documents and settings\Administrator\Application Data\Jumpchinfast
2009-02-18 21:16 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-02-18 21:16 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-02-18 21:16 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-02-18 21:16 --------- d-----w c:\program files\Symantec
2009-02-18 21:15 --------- d-----w c:\program files\Windows Sidebar
2009-02-18 21:15 --------- d-----w c:\program files\Norton Internet Security
2009-02-18 21:15 --------- d-----w c:\documents and settings\All Users\Application Data\Norton
2009-02-18 21:13 --------- d-----w c:\program files\NortonInstaller
2009-02-18 21:13 --------- d-----w c:\documents and settings\All Users\Application Data\NortonInstaller
2009-02-11 04:55 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-02-11 04:15 --------- d-----w c:\program files\Reference Assemblies
2009-02-10 17:11 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-02-10 17:06 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-30 11:57 --------- d-----w c:\program files\MSXML 4.0
2009-01-28 20:16 --------- d-----w c:\documents and settings\All Users\Application Data\Equis
2009-01-28 20:12 --------- d-----w c:\program files\Equis
2009-01-28 20:01 --------- d-----w c:\program files\Wealth-Lab, Inc
2009-01-26 18:19 --------- d-----w c:\program files\KingoOo Upload V3
2009-01-21 19:23 --------- d-----w c:\program files\Clone Terminator
2009-01-21 16:33 --------- d-----w c:\program files\ParetoLogic
2009-01-21 16:33 --------- d-----w c:\documents and settings\All Users\Application Data\DriverCure
2009-01-21 16:33 --------- d-----w c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-01-21 16:33 --------- d-----w c:\documents and settings\Administrator\Application Data\DriverCure
2009-01-19 17:36 --------- d-----w c:\program files\Godlike Developers
2009-01-19 17:36 --------- d-----w c:\documents and settings\Administrator\Application Data\Godlike
2009-01-19 16:00 --------- d-----w c:\program files\Boost Windows
2009-01-19 16:00 --------- d-----w c:\documents and settings\Administrator\Application Data\Boost Windows
2009-01-19 06:43 --------- d-----w c:\program files\Zyzoom
2009-01-16 18:20 --------- d-----w c:\program files\MassSender
2009-01-16 17:15 --------- d-----w c:\documents and settings\All Users\Application Data\Nokia
2009-01-16 17:14 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-01-16 17:14 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-01-16 16:10 --------- d-----w c:\program files\DIFX
2009-01-16 16:10 --------- d-----w c:\documents and settings\All Users\Application Data\PC Suite
2009-01-16 16:10 --------- d-----w c:\documents and settings\Administrator\Application Data\Nokia
2009-01-16 16:08 --------- d-----w c:\documents and settings\Administrator\Application Data\PC Suite
2009-01-16 16:07 --------- d-----w c:\program files\Nokia
2009-01-16 16:07 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2009-01-12 17:43 --------- d-----w c:\program files\TechSmith
2009-01-12 17:43 --------- d-----w c:\documents and settings\All Users\Application Data\TechSmith
2009-01-12 17:40 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-20 11:13 0 ----a-w C:\osy3.sys
2008-11-25 07:07 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008112520081126\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [04/14/2008 09:29 PM 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [12/09/2008 12:15 AM 68856]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [11/24/2008 07:45 PM 2745776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [03/30/2007 08:00 PM 138008]
"Persistence"="c:\windows\system32\igfxpers.exe" [03/30/2007 07:59 PM 138008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [12/14/2008 09:47 AM 136600]
"TomcatStartup"="c:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [03/31/2003 07:28 PM 155648]
"SigmatelSysTrayApp"="stsystra.exe" [10/29/2006 06:17 PM 397312 c:\windows\stsystra.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 09:29 PM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-01-29 576104]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChange*********"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"HideClock"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\groove.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\IEPro\\MiniDM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"c:\\Program Files\\Mobily Connect Card\\Mobily Connect Card.exe"=
R0 SymEFA;Symantec Extended File Attributes;\SystemRoot\\SystemRoot\System32\Drivers\NIS\1002000.007\SYMEFA.SYS --> \SystemRoot\\SystemRoot\System32\Drivers\NIS\1002000.007\SYMEFA.SYS [?]
R0 ulsata2;ulsata2;c:\windows\system32\drivers\ulsata2.sys [2008-05-07 124928]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1002000.007\BHDrvx86.sys [2009-02-20 255536]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1002000.007\cchpx86.sys [2009-02-20 362544]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090225.002\IDSxpx86.sys [2009-02-28 276344]
R2 DBSERVER;Antamedia Database Server Service;c:\antamedia\DBServer\DBServer.exe [2008-12-01 1118720]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe [2009-02-20 115560]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-02-26 603904]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-19 101936]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2689433f-d069-11dd-a8ee-001302c1eb5b}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6563aae0-fd29-11dd-a9c9-001302c1eb5b}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f26dcf8d-bac2-11dd-a8a0-0015c56117e5}]
\Shell\AutoRun\command - F:\AutoRun.exe
.
*******s of the 'Scheduled Tasks' folder
2009-03-04 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [12/31/2008 05:04 PM]
2009-02-11 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [12/31/2008 05:04 PM]
2009-03-04 c:\windows\Tasks\AC9DB506915A25C6.job
- c:\docume~1\admini~1\applic~1\jumpch~1\POPTICKSAFE.exe [02/21/2009 10:48 PM]
2009-03-04 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [11/20/2008 04:28 PM]
2009-03-04 c:\windows\Tasks\الصيانة بنقرة واحدة.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [11/20/2008 04:28 PM]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = <local>
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
IE: {{000002a3-84fe-43f1-b958-f2c3ca804f1a} - {CD275D4E-791A-4993-9D4D-6A071EDD2709} - c:\program files\IEPro\iepro.dll
TCP: {47F6AF9E-0765-46D4-A9FB-D0A7D518F513} = 192.168.1.254
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\Norton Internet Security\Engine\16.2.0.7\CoIEPlg.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-03-04 13:51:48
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.2.0.7\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1924)
c:\windows\system32\btmmhook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\WgaTray.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\Internet Download Manager\IEMonitor.exe
c:\program files\Mubasher\Mubasher Pro\TWR.exe
c:\windows\system32\WBEM\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 03/04/2009 13:55:30 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-04 10:55:14
ComboFix3.txt 2008-12-24 05:16:48
ComboFix2.txt 2009-02-26 08:01:36
Pre-Run: 18,044,813,312 bytes free
Post-Run: 18,271,600,640 bytes free
214 --- E O F --- 2009-02-28 18:08:39