ComboFix 08-07-29.1 - Administrator 2008-07-30 6:03:41.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.697 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20020823.004\DESKTOP_.INI
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080319.003\DESKTOP_.INI
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080722.003\DESKTOP_.INI
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com
.
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-30 )))))))))))))))))))))))))))))))
.
2008-07-30 05:33 . 2008-07-30 05:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-30 02:00 . 2008-07-30 02:00 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-07-30 02:00 . 2008-03-17 23:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-30 01:59 . 2008-07-30 01:59 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\zMicroWorld_Anti_Virus
2008-07-30 01:59 . 2002-08-28 19:41 134,144 --a------ C:\WINDOWS\R.COM
2008-07-30 01:59 . 2002-08-28 19:41 128,512 --a------ C:\WINDOWS\system32\T.COM
2008-07-30 01:22 . 2008-07-30 01:22 <DIR> d-------- C:\Program Files\Unlocker
2008-07-29 10:16 . 2008-07-29 10:16 <DIR> d-------- C:\Program Files\Exterminate It!
2008-07-29 10:09 . 2008-07-29 10:09 <DIR> d-------- C:\Program Files\XoftSpy
2008-07-29 08:26 . 2008-07-29 08:26 <DIR> d-------- C:\Program Files\FinalData
2008-07-27 08:11 . 2008-07-27 08:11 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2008-07-26 16:00 . 2008-07-26 16:00 <DIR> d-------- C:\Program Files\Trojan Remover
2008-07-26 15:17 . 2004-08-03 14:00 420,632 --a------ C:\WINDOWS\system32\wuapi.dll
2008-07-26 15:17 . 2004-08-03 14:03 186,136 --a------ C:\WINDOWS\system32\wuaueng1.dll
2008-07-26 15:17 . 2004-08-03 14:03 167,704 --a------ C:\WINDOWS\system32\wuaucpl.cpl
2008-07-26 15:17 . 2004-08-03 14:01 167,704 --a------ C:\WINDOWS\system32\wuauclt1.exe
2008-07-26 15:17 . 2004-08-03 13:59 120,288 --a------ C:\WINDOWS\system32\wuweb.dll
2008-07-26 15:17 . 2004-08-03 14:02 118,552 --a------ C:\WINDOWS\system32\wucltui.dll
2008-07-26 15:17 . 2004-08-03 13:59 39,704 --a------ C:\WINDOWS\system32\wups.dll
2008-07-25 00:56 . 2008-07-29 07:43 49 --a------ C:\WINDOWS\NeroDigital.ini
2008-07-24 16:48 . 2008-07-24 16:48 268 --ah----- C:\sqmdata05.sqm
2008-07-24 16:48 . 2008-07-24 16:48 244 --ah----- C:\sqmnoopt05.sqm
2008-07-24 13:15 . 2008-07-24 13:15 268 --ah----- C:\sqmdata04.sqm
2008-07-24 13:15 . 2008-07-24 13:15 244 --ah----- C:\sqmnoopt04.sqm
2008-07-24 08:21 . 2008-07-24 08:21 268 --ah----- C:\sqmdata03.sqm
2008-07-24 08:21 . 2008-07-24 08:21 244 --ah----- C:\sqmnoopt03.sqm
2008-07-24 08:14 . 2008-07-24 08:14 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-07-24 08:10 . 2008-07-24 08:10 <DIR> d-------- C:\Program Files\Your Uninstaller 2008
2008-07-24 08:10 . 2008-07-24 08:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-24 08:02 . 2008-07-24 08:02 268 --ah----- C:\sqmdata02.sqm
2008-07-24 08:02 . 2008-07-24 08:02 244 --ah----- C:\sqmnoopt02.sqm
2008-07-24 07:58 . 2008-07-24 07:58 268 --ah----- C:\sqmdata01.sqm
2008-07-24 07:58 . 2008-07-24 07:58 244 --ah----- C:\sqmnoopt01.sqm
2008-07-24 07:55 . 2008-07-24 07:55 268 --ah----- C:\sqmdata00.sqm
2008-07-24 07:55 . 2008-07-24 07:55 244 --ah----- C:\sqmnoopt00.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-22 18:43 32 --sha-w C:\WINDOWS\{5116FD56-A2A4-476F-ABC6-22A8B2995BCB}.dat
2008-03-22 18:43 32 --sha-w C:\WINDOWS\system32\{2A431656-28C9-44DB-886F-B12CB8921ADC}.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:55 5674352]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-07-24 08:08 2594224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2002-08-19 22:22 50880]
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-08-19 22:23 34504]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-22 21:45 180269]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 20:19 15872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-08-28 19:41 13312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.vp31"= vp31vfw.dll
*Newly Created Service* - CATCHME
*Newly Created Service* - KLIF
*Newly Created Service* - PROCEXP90
*Newly Created Service* - UNLOCKERDRIVER5
.
s of the 'Scheduled Tasks' folder
2008-07-25 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job
- C:\PROGRA~1\NORTON~1\NAVW32.exe [2002-11-14 19:31]
2008-07-30 C:\WINDOWS\Tasks\Symantec NetDetect.job
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE [2002-08-07 09:04]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/
R1 -: HKCU-Internet Settings,ProxyOverride = local
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 -: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
O16 -: Microsoft XML Parser for Java -
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-30 06:04:55
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-30 6:05:27
ComboFix-quarantined-files.txt 2008-07-30 03:05:26
Pre-Run: 16,098,869,248 bytes free
Post-Run: 16,352,837,632 bytes free
112