ComboFix 08-07-13.6 - JWS 07/14/2008 5:14:09.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.180 [GMT 3:00]
Running from: C:\Documents and Settings\JWS\سطح المكتب\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Documents\My Videos\Desktop.ini
C:\Documents and Settings\JWS\Application Data\tazebama
C:\Documents and Settings\JWS\My Documents\My Videos\Desktop.ini
C:\WINDOWS\svchost.ini
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\Ultra.dll
C:\WINDOWS\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-14 to 2008-07-14 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-14 02:20 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-14 02:20 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-14 02:20 17,952 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-14 02:20 1,220 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-14 02:00 --------- d-----w C:\Documents and Settings\JWS\Application Data\Grisoft
2008-07-14 01:06 3,008 ----a-w C:\WINDOWS\system32\tmp.reg
2008-07-14 00:53 --------- d-----w C:\Documents and Settings\JWS\Application Data\CyberScrub
2008-07-14 00:53 --------- d-----w C:\Documents and Settings\JWS\Application Data\cleaner
2008-07-13 00:22 --------- d-----w C:\Program Files\Realtek AC97
2008-07-12 17:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-07-12 03:40 --------- d-----w C:\Program Files\Video-AVI to GIF-JPEG
2008-07-12 00:34 --------- d-----w C:\Program Files\Foxit PDF Tools
2008-07-11 23:26 --------- d-----w C:\Program Files\Dream Aquarium
2008-07-11 22:45 --------- d-----w C:\Program Files\Intel
2008-07-11 15:59 64,331 ----a-w C:\WINDOWS\system32\lrrbgosokwzr.exe
2008-07-11 11:17 --------- d-----w C:\Program Files\ACE Mega CoDecS Pack
2008-07-10 12:55 --------- d-----w C:\Program Files\ma-config.com
2008-07-10 12:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-07-10 02:24 --------- d-----w C:\Program Files\Internet Download Manager
2008-07-10 02:09 96,966 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-07-10 02:09 88,774 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-10 01:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-09 23:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\zyz Kaspersky Lab setup files
2008-07-09 22:00 60,416 ----a-w C:\WINDOWS\ALCFDRTM.EXE
2008-07-09 20:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-07-09 19:48 96,520 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys.install_backup
2008-07-09 19:48 76,040 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys.install_backup
2008-07-09 19:48 26,824 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys.install_backup
2008-07-09 19:48 12,936 ----a-w C:\WINDOWS\system32\drivers\avgrkx86.sys.install_backup
2008-07-09 16:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-07-09 15:28 --------- d-----w C:\Program Files\TechSmith
2008-07-09 15:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\TechSmith
2008-07-09 15:26 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-08 22:22 98,304 ----a-w C:\WINDOWS\system32\viscomtran.dll
2008-07-08 22:21 --------- d-----w C:\Program Files\Ozone
2008-07-08 08:11 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-07-08 08:11 --------- d-----w C:\Program Files\Adobe Media Player
2008-07-08 02:55 --------- d-----w C:\Documents and Settings\JWS\Application Data\Thinstall
2008-07-07 22:18 --------- d-----w C:\Program Files\Sun
2008-07-07 21:54 --------- d-----w C:\Documents and Settings\JWS\Application Data\Nero
2008-07-07 21:37 --------- d-----w C:\Program Files\TaskSwitchXP
2008-07-07 21:34 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-07-07 21:34 218,624 ----a-w C:\WINDOWS\system32\dllcache\uxtheme.dll
2008-07-07 21:29 --------- d-----w C:\Program Files\MSN Messenger
2008-07-07 21:27 --------- d-----w C:\Program Files\Nero
2008-07-07 21:27 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 3
2008-07-07 21:27 --------- d-----w C:\Program Files\Common Files\Nero
2008-07-07 21:14 --------- d-----w C:\Program Files\Java
2008-07-07 21:14 --------- d-----w C:\Program Files\Common Files\Java
2008-07-07 21:13 --------- d-----w C:\Program Files\Apple Software Update
2008-07-07 21:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-07-07 21:12 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-07-07 21:12 --------- d-----w C:\Program Files\Mohsoft
2008-07-07 21:06 --------- d-----w C:\Documents and Settings\JWS\Application Data\Apple Computer
2008-07-07 19:06 --------- d-----w C:\Documents and Settings\JWS\Application Data\Yahoo!
2008-07-07 19:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-07-06 00:32 --------- d-----w C:\Program Files\XP TCPIP Repair
2008-06-30 13:52 --------- d-----w C:\Program Files\SoftwareDoctor
2008-06-30 13:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\GRETECH
2008-06-30 13:48 --------- d-----w C:\Documents and Settings\JWS\Application Data\GRETECH
2008-06-30 13:47 --------- d-----w C:\Program Files\GRETECH
2008-06-30 13:33 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-06-30 13:33 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-30 12:52 --------- d-----w C:\Program Files\Yahoo!
2008-06-29 20:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-06-29 18:53 --------- d-----w C:\Program Files\Your Uninstaller 2008
2008-06-29 18:53 --------- d-----w C:\Documents and Settings\JWS\Application Data\URSoft
2008-06-29 15:29 --------- d-----w C:\Program Files\Trojan Remover
2008-06-29 15:29 --------- d-----w C:\Documents and Settings\JWS\Application Data\Simply Super Software
2008-06-29 15:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-06-27 16:04 373,760 ----a-w C:\WINDOWS\system32\iqluyidjqrsmicbu.dll
2008-06-20 20:09 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 17:39 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:39 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 12:22 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 12:22 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-14 17:59 271,616 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 17:59 271,616 ----a-w C:\WINDOWS\system32\dllcache\bthport.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:14 1,285,632 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:14 1,285,632 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-28 05:03 82,944 ----a-w C:\WINDOWS\system32\IEDFix.exe
2008-04-28 05:03 82,944 ----a-w C:\WINDOWS\system32\404Fix.exe
2008-04-25 15:22 206,088 ----a-w C:\WINDOWS\system32\klogon.dll
2008-04-24 05:10 86,528 ----a-w C:\WINDOWS\system32\VACFix.exe
2008-04-23 19:16 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-22 07:38 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:38 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-20 05:07 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
.
------- Sigcheck -------
06/13/2007 04:22 PM 1384448 bda677c3f59dfb7ece160cb80552a534 C:\WINDOWS\explorer.exe
06/13/2007 04:22 PM 1384448 bda677c3f59dfb7ece160cb80552a534 C:\WINDOWS\system32\dllcache\explorer.exe
06/13/2007 04:10 PM 1030656 d0dc9258122f39129966649085f45880 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
08/03/2004 09:56 PM 1029632 932f97b77f2625f7ff7dfc97552548f8 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
06/13/2007 04:22 PM 1030656 4e877303248a09847fb303ee173fbd70 C:\WINDOWS\Fedora Transformation Pack\Backup\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 09:56 PM 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [07/08/2008 04:59 AM 171448]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [11/06/2007 07:51 PM 3810544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" [11/03/2007 04:50 AM 6731312]
"SDaemon"="C:\WINDOWS\sdaemon.exe" [04/19/2005 12:57 AM 111104]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [06/03/2008 08:33 PM 878672]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM 39792]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [11/02/2004 04:03 AM 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [11/02/2004 03:59 AM 126976]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/03/2004 09:56 PM 110592 C:\WINDOWS\system32\bthprops.cpl]
"SoundMan"="SOUNDMAN.EXE" [07/22/2005 10:00 AM 81920 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/03/2004 09:56 PM 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM]
R0 WINSEC;WINSEC;C:\WINDOWS\system32\drivers\WINSEC.SYS [04/19/2005 12:57 AM]
R2 drhard;drhard;C:\WINDOWS\system32\drivers\drhard.sys [12/01/2005 10:49 AM]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [03/25/2008 08:07 PM]
S3 SetupNTGLM7X;SetupNTGLM7X;F:\NTGLM7X.sys []
S3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [06/08/2007 09:52 AM]
S4 winser;winser;C:\WINDOWS\system32\winsersec.exe [04/14/2005 01:37 AM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\setup.exe
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-DriveDiscoveryMemoryResident - C:\Program Files\NotsoSoftware\DriveDiscovery\NSSMR.exe
HKCU-Run-WMPNSCFG - C:\Program Files\Windows Media Player\WMPNSCFG.exe
HKLM-Run-msnappau - C:\Program Files\MSN Apps\Updater\
01.02.3000.1001\ar-xa\msnappau.exe
HKLM-Run-SWd - C:\WINDOWS\winwd.exe
HKLM-Run-zyz1 - c:\zyz_auto_killer\run2.exe
HKLM-Run-SystemInit - (no file)
HKLM-Run-Karen - (no file)
HKLM-Run-raVe - (no file)
HKLM-Run-Win32BaseServiceMOD - (no file)
HKLM-Run-startIE - (no file)
HKLM-RunServices-raVe - (no file)
HKLM-RunServices-Driver32 - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-14 05:22:50
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\SYSTEM32\CRYPSERV.EXE
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSSRVC.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
.
**************************************************************************
.
Completion time: 07/14/2008 5:26:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-14 02:25:58
Pre-Run: 18,053,300,224 bytes free
Post-Run: 17,992,433,664 bytes free
235 --- E O F --- 2008-07-14 00:19:05