تقرير ComboFix
--------
ComboFix 08-07-09.2 - Free User 07/10/2008 5:11:47.2 - NTFSx86
Running from: C:\Documents and Settings\Free User\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\antispy2
C:\Program Files\antispy2\anti_spy.exe
C:\Program Files\antispy2\s.txt
C:\Program Files\antispy2\Uninstall\IRIMG1.JPG
C:\Program Files\antispy2\Uninstall\IRIMG2.JPG
C:\Program Files\antispy2\Uninstall\IRIMG3.JPG
C:\Program Files\antispy2\Uninstall\uninstall.dat
C:\Program Files\antispy2\Uninstall\uninstall.xml
.
((((((((((((((((((((((((( Files Created from 2008-06-10 to 2008-07-10 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-10 02:23 21,652,768 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-10 02:20 460,832 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-10 02:16 44,180 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-10 02:16 292,016 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-29 15:46 --------- d-----w C:\Documents and Settings\Free User\Application Data\Vso
2008-06-25 09:19 --------- d-----w C:\Documents and Settings\Free User\Application Data\Internet Download Accelerator
2008-06-21 06:47 --------- d-----w C:\Program Files\Java
2008-06-14 18:41 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-11 21:18 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2008-06-08 16:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
2008-06-08 16:24 --------- d-----w C:\Program Files\Common Files\Merge Modules
2008-06-08 16:23 --------- d-----w C:\Program Files\HTML Help Workshop
2008-06-08 14:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-06 14:05 --------- d-----w C:\Program Files\Real
2008-06-06 14:05 --------- d-----w C:\Program Files\Common Files\Real
2008-05-30 16:51 --------- d-----w C:\Program Files\Emplyees
2008-05-30 09:16 88,774 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-05-29 03:21 96,966 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-05-29 03:21 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-05-28 03:23 --------- d-----w C:\Program Files\MSN Messenger
2008-05-28 03:23 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-05-13 22:38 --------- d-----w C:\Documents and Settings\Free User\Application Data\Talkback
2008-05-12 11:47 --------- d-----w C:\Program Files\Ashampoo
2005-06-22 05:37 45,568 --sha-r C:\WINDOWS\system32\cygz.dll
2008-01-04 05:19 23 --sha-w C:\WINDOWS\system32\edabc7_d.dll
2007-05-10 16:06 140 --sha-r C:\WINDOWS\system32\run.reg
.
(((((((((((((((((((((((((((((
snapshot@Tue 07-08-2008_ 2.31.45.81 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-07 23:22:20 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-10 02:17:17 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2007-05-10 22:31:36 65,536 ----a-r C:\WINDOWS\Installer\{236BB7C4-4419-42FD-0409-1E257A25E34D}\NewShortcut1_236BB7C4441942FD04091E257A25E34D.exe
+ 2008-06-08 16:21:53 65,536 ----a-r C:\WINDOWS\Installer\{236BB7C4-4419-42FD-0409-1E257A25E34D}\NewShortcut1_236BB7C4441942FD04091E257A25E34D.exe
- 2008-07-07 23:22:34 16,384 --sha-w C:\WINDOWS\system32\config\systemprofile\s\index.dat
+ 2008-07-10 02:17:36 16,384 --sha-w C:\WINDOWS\system32\config\systemprofile\s\index.dat
- 2008-07-07 23:22:34 16,384 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-07-10 02:17:36 16,384 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-07-07 23:22:34 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\.IE5\index.dat
+ 2008-07-10 02:17:36 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\.IE5\index.dat
- 2008-07-07 12:08:15 786,000 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-06-11 21:04:53 782,816 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2008-03-30 14:49:36 58,596 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-06-08 15:59:52 51,260 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-30 14:49:36 392,296 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-06-08 15:59:53 336,916 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [12/31/2002 12:00 PM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [03/11/2003 04:24 AM 155648]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/06/2008 05:05 PM 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [06/21/2008 09:47 AM 77824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\CTFMON.EXE" [12/31/2002 12:00 PM 15360]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
«©م، ¢¬نïé Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 07:05:26 29696]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoRun"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Free User^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Free User^Start Menu^Programs^Startup^برنامج الإختصارات العربي.lnk]
backup=C:\WINDOWS\pss\برنامج الإختصارات العربي.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
-ra------ 03/11/2003 04:11 AM 114688 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 02/19/2006 02:41 AM 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 10/13/2004 07:24 PM 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 10/18/2007 11:34 AM 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP]
--a------ 05/24/2006 09:31 PM 1372160 C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Documents and Settings\\All Users.WINDOWS\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.321\\English\\setup.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 7.0\\avp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP

oVoo TCP port 443
"443:UDP"= 443:UDP

oVoo UDP port 443
"37674:TCP"= 37674:TCP

oVoo TCP port 37674
"37674:UDP"= 37674:UDP

oVoo UDP port 37674
"37675:UDP"= 37675:UDP

oVoo UDP port 37675
R2 LF30FS;LF30FS;C:\Program Files\Everstrike Software\Lock Folder XP 3.5\LF30XP.sys [11/19/2004 05:07 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [12/13/2007 01:28 PM]
R3 MTD80X;100/10M Ethernet PCI Adapter;C:\WINDOWS\system32\DRIVERS\FEAND5.SYS [11/15/2001 02:12 AM]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [12/16/2006 11:37 PM]
.
s of the 'Scheduled Tasks' folder
"2008-07-08 05:19:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-swg - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-10 05:20:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
.
**************************************************************************
.
Completion time: 07/10/2008 5:35:11 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-10 02:34:33
ComboFix2.txt 2008-07-07 23:34:12
Pre-Run: 4,843,888,640 bytes free
Post-Run: 5,086,453,760 bytes free
184 --- E O F --- 2008-02-13 11:42:27