ComboFix 08-07-26.1 - وحيد الودعاني 07/27/2008 15:40:50.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1256.1.1025.18.149 [GMT 3:00]
Running from: C:\Documents and Settings\وحيد الودعاني\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\ADSTechnology
C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\ADSTechnology\ADSTechnology.lnk
C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\ADSTechnology\Uninstall.lnk
C:\Program Files\ActivationManager
C:\Program Files\ActivationManager\Uninstall.exe
C:\Program Files\ADSTechnology
C:\Program Files\ADSTechnology\ADSTechnology.exe
C:\Program Files\ADSTechnology\Uninstall.exe
C:\Program Files\Antivirus 2009
C:\Program Files\Antivirus 2009\av2009.exe.tmp
C:\WINDOWS\BMcf04da30.txt
C:\WINDOWS\s.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system\oeminfo.ini
C:\WINDOWS\system32\hgGaaWpQ.dll
C:\WINDOWS\system32\hgGwTJCt.dll
C:\WINDOWS\system32\jxrywlhx.ini
C:\WINDOWS\system32\LRuFNnpo.ini
C:\WINDOWS\system32\LRuFNnpo.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\opnNFuRL.dll
C:\WINDOWS\system32\rditklxc.dll
C:\WINDOWS\system32\vepxwnnv.ini
C:\WINDOWS\system32\wqnadonn.ini
.
((((((((((((((((((((((((( Files Created from 2008-06-27 to 2008-07-27 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-28 04:27 --------- d-----w C:\Program Files\Java
2008-07-27 12:45 532,512 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-27 12:45 3,948 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-27 12:45 2,132,512 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-27 12:45 19,836 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-27 06:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-27 01:06 --------- d-----w C:\Program Files\Google
2008-07-26 20:29 --------- d-----w C:\Program Files\PowerArchiver
2008-07-26 08:07 --------- d-----w C:\Program Files\IObit
2008-07-26 05:30 --------- d-----w C:\Program Files\Opera
2008-07-25 12:34 --------- d-----w C:\Program Files\Bonjour
2008-07-25 12:33 --------- d-----w C:\Program Files\Apple Software Update
2008-07-25 12:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-07-25 11:54 --------- d-----w C:\Program Files\CCleaner
2008-07-25 11:53 --------- d-----w C:\Program Files\Yahoo!
2008-07-25 09:29 --------- d-----w C:\Program Files\Avant Browser
2008-07-24 12:38 96,559 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-07-24 12:38 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-16 13:31 --------- d-----w C:\Program Files\Aplus Video To 3GP Converter
2008-07-08 23:32 --------- d-----w C:\Program Files\Paltalk Messenger
2008-07-06 23:29 --------- d-----w C:\Program Files\Extension Changer
2008-07-06 10:18 --------- d-----w C:\Program Files\Easy Photo Recovery
2008-07-05 11:31 --------- d-----w C:\Program Files\LtUcx
2008-07-05 11:13 --------- d-----w C:\Program Files\Common Files\Ahead
2008-07-05 11:12 --------- d-----w C:\Program Files\SplitCam
2008-06-21 21:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-21 21:59 --------- d-----w C:\Program Files\Firegraphic
2008-06-21 21:45 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 15:16 --------- d-----w C:\Program Files\ESTsoft
2008-06-19 13:33 --------- d-----w C:\Program Files\Common Files\Nero
2008-06-19 13:30 --------- d-----w C:\Program Files\Nero
2008-06-19 13:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-06-19 13:25 --------- d-----w C:\Program Files\AskTBar
2008-06-19 00:44 --------- d-----w C:\Program Files\Common Files\xing shared
2008-06-19 00:43 --------- d-----w C:\Program Files\Common Files\Real
2008-06-16 02:10 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-15 21:09 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-06-15 20:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-06-15 16:14 --------- d-----w C:\Program Files\Artera Turbo
2008-06-15 00:36 --------- d-----w C:\Program Files\Internet Download Manager
2008-06-14 23:24 --------- d-----w C:\Program Files\TuneUp Utilities 2007
2008-06-14 23:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-06-14 23:20 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-14 17:59 271,616 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2007-09-04 21:33 84,418 ----a-w C:\Documents and Settings\All Users\Application Data\firstlsp.reg.dat
2007-08-24 12:05 82 ----a-w C:\Documents and Settings\All Users\Application Data\SUMQU0C1-FE20-APII-YE7M-BEDSDWMY5R6A.dat
.
------- Sigcheck -------
06/13/2007 04:22 PM 1880576 26540a4df9b4ff5541ac67cc71ec1988 C:\WINDOWS\explorer.exe
06/13/2007 04:10 PM 1030656 d0dc9258122f39129966649085f45880 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
03/02/2006 03:00 PM 1029632 932f97b77f2625f7ff7dfc97552548f8 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [03/02/2006 03:00 PM 15360]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [02/28/2008 06:07 PM 1828136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM 144784]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [12/05/2006 10:55 PM 54832]
"BCWipeTM Startup"="C:\Program Files\Jetico\BCWipe\BCWipeTM.exe" [02/08/2008 10:35 AM 545520]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/19/2008 03:40 AM 185896]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [04/28/2008 05:14 PM 570664]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [02/18/2008 05:29 PM 2221352]
"cc37e9ac"="C:\WINDOWS\system32\nnodanqw.dll" [07/27/2008 06:59 AM 83456]
"BMcf04da30"="C:\WINDOWS\system32\ueapnfgg.dll" [07/27/2008 06:56 AM 91648]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [03/02/2006 03:00 PM 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [06/19/2007 10:17 AM 1241088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SSS2006"="C:\Program Files\Steganos Security Suite 2006\SSS2006.exe" [05/24/2006 01:54 PM 5279744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.FMVC"= fmcodec.dll
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Orbit.lnk]
path=C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Orbit.lnk
backup=C:\WINDOWS\pss\Orbit.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalStart.lnk]
path=C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalStart.lnk
backup=C:\WINDOWS\pss\PalStart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
path=C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalTalk.lnk
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^SnagIt 8.lnk]
path=C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\SnagIt 8.lnk
backup=C:\WINDOWS\pss\SnagIt 8.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^وحيد الودعاني^قائمة ابدأ^البرامج^بدء التشغيل^Stardock Dock.lnk]
path=C:\Documents and Settings\وحيد الودعاني\قائمة ابدأ\البرامج\بدء التشغيل\Stardock Dock.lnk
backup=C:\WINDOWS\pss\Stardock Dock.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^وحيد الودعاني^قائمة ابدأ^البرامج^بدء التشغيل^UberIcon.lnk]
path=C:\Documents and Settings\وحيد الودعاني\قائمة ابدأ\البرامج\بدء التشغيل\UberIcon.lnk
backup=C:\WINDOWS\pss\UberIcon.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^وحيد الودعاني^قائمة ابدأ^البرامج^بدء التشغيل^Y'z Shadow.lnk]
path=C:\Documents and Settings\وحيد الودعاني\قائمة ابدأ\البرامج\بدء التشغيل\Y'z Shadow.lnk
backup=C:\WINDOWS\pss\Y'z Shadow.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AFProg]
--a------ 11/20/2006 11:19 AM 81920 C:\Program Files\AnchorFree\bin\ctrl\AFController.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 03/02/2006 03:00 PM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
-ra------ 11/28/2005 08:52 AM 77824 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
-ra------ 11/28/2005 08:55 AM 118784 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
-ra------ 11/28/2005 08:55 AM 98304 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 10/18/2007 11:34 AM 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 06/18/2007 03:10 PM 271360 C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 11/23/2006 03:10 PM 56928 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSS2006]
--a------ 05/24/2006 01:54 PM 5279744 C:\Program Files\Steganos Security Suite 2006\SSS2006.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
-ra------ 10/14/2007 06:09 PM 103712 C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 06/19/2008 03:40 AM 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-ra------ 05/03/2005 01:43 PM 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-ra------ 11/14/2006 12:21 PM 16270848 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-ra------ 05/16/2006 01:04 PM 2879488 C:\WINDOWS\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Avant Browser\\avant.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.289\\English\\setup.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM]
R1 SLEE_13_DRIVER;Steganos Live Encryption Engine 13 [Driver];C:\WINDOWS\system32\drivers\SLEE13.sys [10/04/2005 06:42 PM]
R2 Steganos AntiTheft;Steganos AntiTheft;C:\WINDOWS\system32\\SatSrv.exe [05/24/2006 01:23 PM]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [03/02/2006 03:00 PM]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [03/25/2008 08:07 PM]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [12/16/2006 11:37 PM]
S3 KBNTXP;Standard PS/2 Multi-Keyboard Filter Driver for WinXp;C:\WINDOWS\system32\DRIVERS\KBNTXP.sys [11/12/2004 03:32 PM]
S3 MPNatDrv;Artera NAT Driver;C:\WINDOWS\system32\DRIVERS\mpnat2k.sys []
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [08/03/2004 11:01 PM]
S4 BCSWAP;BCSWAP;C:\WINDOWS\system32\drivers\BCSWAP.sys [09/14/2007 07:46 AM]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{60519760-1137-11dd-8492-001a4d275b68}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL explore.exe
.
s of the 'Scheduled Tasks' folder
2008-07-25 C:\WINDOWS\Tasks\1-Click Maintenance.job - s !;C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe/schedulestartH-J/ 'DH/9'FJ,Runs 1-Click Maintenance at specified times0 []
2008-07-25 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - s!:C:\Program Files\Apple Software Update\SoftwareUpdate.exe-taskSYSTEM0 []
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-IDMan - C:\Documents and Settings\وحيد الودعاني\سطح المكتب\مجلد جديد\Internet.Download.Manager.5.12.Build.8.CRACK\Crack\IDMan.exe
MSConfigStartUp-AVP - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
MSConfigStartUp-Free Download Manager - C:\Program Files\Free Download Manager\fdm.exe
MSConfigStartUp-Free Upload Manager - C:\Program Files\Free Download Manager\fum\fum.exe
MSConfigStartUp-Free Uploader Oe Integration - C:\Program Files\Free Download Manager\FUM\fumoei.exe
MSConfigStartUp-TrojanScanner - C:\Program Files\Trojan Remover\Trjscan.exe
MSConfigStartUp-VistaStart1 - C:\WINDOWS\Resources\Themes\Vista_Anthracite\VistaStart\VistaStart1.3.exe
.
------- Supplementary Scan -------
.
O8 -: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 -: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 -: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 -: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Documents and Settings\وحيد الودعاني\سطح المكتب\مجلد جديد\Internet.Download.Manager.5.12.Build.8.CRACK\Crack\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - C:\Documents and Settings\وحيد الودعاني\سطح المكتب\مجلد جديد\Internet.Download.Manager.5.12.Build.8.CRACK\Crack\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Documents and Settings\وحيد الودعاني\سطح المكتب\مجلد جديد\Internet.Download.Manager.5.12.Build.8.CRACK\Crack\IEGetVL.htm
O16 -: Microsoft XML Parser for Java -
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-27 15:47:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Documents and Settings\C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\system32\SatSrv.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\C:\WINDOWS\system32\wbem\wmiprvse.exe
.
**************************************************************************
.
Completion time: 07/27/2008 15:50:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-27 12:50:16
Pre-Run: 13,420,482,560 bytes free
Post-Run: 13,379,121,152 bytes free
258 --- E O F --- 2008-07-09 14:45:21