ComboFix 08-11-06.01 - Administrator 11/07/2008 16:26:42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.71 [GMT 3:00]
Running from: c:\documents and settings\Administrator\My Documents\الملفات المتلقاة\ComboFix\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\Administrator\Application Data\tazebama
c:\documents and settings\Administrator\Application Data\tazebama\tazebama.log
c:\documents and settings\Administrator\Application Data\tazebama\zPharaoh.dat
c:\windows\IE4 Error Log.txt
c:\windows\system32\amvo.exe
c:\windows\system32\amvo0.dll
c:\windows\system32\amvo1.dll
c:\windows\system32\kakle.dll
C:\zPharaoh.exe
D:\Autorun.inf
D:\zPharaoh.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-07 to 2008-11-07 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-07 13:32 925,039 ----a-w c:\windows\pchealth\helpctr\binaries\helpctr.exe
2008-11-07 13:32 314,735 ----a-w c:\windows\pchealth\helpctr\binaries\msconfig.exe
2008-11-07 13:32 155,621 --sh--r C:\zPharaoh.exe
2008-11-07 13:32 --------- d-----w c:\program files\SpeedBit Video Accelerator
2008-11-07 13:32 --------- d-----w c:\documents and settings\Administrator\Application Data\tazebama
2008-11-07 11:48 --------- d-----w c:\program files\Face.Smoother
2008-11-07 11:22 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-11-07 11:07 --------- d-----w c:\program files\Golden Al-Wafi Translator
2008-11-06 21:22 877,423 ----a-w c:\windows\iun6002.exe
2008-11-06 21:22 463,215 ----a-w c:\windows\IsUninst.exe
2008-11-06 21:22 398,191 ----a-w c:\windows\system32\zhhp1600.exe
2008-11-06 21:22 246,639 ----a-w c:\windows\unvise32.exe
2008-11-06 21:21 456,047 ----a-w c:\windows\uninst.exe
2008-11-06 21:21 372,591 ----a-w c:\windows\iun3405.exe
2008-11-06 21:21 307,381 ----a-w c:\windows\UnDsp.EXE
2008-11-06 21:21 305,007 ----a-w c:\windows\UNWISE.EXE
2008-11-06 21:21 229,743 ----a-w c:\windows\ST6UNST.EXE
2008-11-06 07:08 --------- d-----w c:\documents and settings\Administrator\Application Data\knobthe
2008-11-04 19:58 327,680 ----a-w c:\windows\system32\dfxg11.dll
2008-11-04 19:58 --------- d-----w c:\program files\Winamp
2008-11-04 19:58 --------- d-----w c:\program files\Sonique
2008-11-04 19:58 --------- d-----w c:\program files\DFX
2008-11-04 19:57 --------- d-----w c:\program files\DSPFX Virtual Pack
2008-11-04 19:53 --------- d-----w c:\program files\RayGun
2008-11-04 19:51 --------- d-----w c:\program files\Sonic Foundry Plug-Ins
2008-11-04 19:51 --------- d-----w c:\program files\Sonic Foundry MP3 Plug-In
2008-11-04 19:51 --------- d-----w c:\program files\Sonic Foundry ACID 2.0
2008-11-04 19:50 --------- d-----w c:\program files\Timeworks
2008-11-04 19:50 --------- d-----w c:\program files\Sonic Foundry
2008-11-04 19:44 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-04 19:44 --------- d-----w c:\program files\Waves
2008-11-04 19:44 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-04 13:46 --------- d-----w c:\program files\Super Audio Converter
2008-11-03 21:23 13,344 ----a-w c:\windows\system32\drivers\NEROCDNT.SYS
2008-11-03 21:22 --------- d-----w c:\program files\Wav to Mp3 Encoder
2008-11-03 21:22 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-03 21:20 --------- d-----w c:\program files\2B System
2008-11-03 21:19 --------- d-----w c:\program files\MP3CD
2008-11-03 21:19 --------- d-----w c:\program files\Acoustica
2008-10-31 10:07 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-10-27 16:11 --------- d-----w c:\program files\The KMPlayer
2008-10-27 11:52 90,112 ----a-w c:\windows\system32\agsaami.dll
2008-10-27 11:52 610,304 ----a-w c:\windows\system32\agsaamg.dll
2008-10-27 11:52 372,736 ----a-w c:\windows\system32\agsaamc.dll
2008-10-27 11:52 2,535,424 ----a-w c:\windows\system32\agsaamj.dll
2008-10-27 11:52 196,608 ----a-w c:\windows\system32\maag.dll
2008-10-27 11:52 1,986,560 ----a-w c:\windows\system32\akll.dll
2008-10-27 11:52 1,245,184 ----a-w c:\windows\system32\bkll.dll
2008-10-27 11:52 1,212,416 ----a-w c:\windows\system32\ckll.dll
2008-10-27 11:52 --------- d-----w c:\program files\Real_SC
2008-10-25 20:47 --------- d-----w c:\program files\Common Files\Adobe Systems Shared
2008-10-25 20:47 --------- d-----w c:\documents and settings\All Users\Application Data\Adobe Systems
2008-10-25 20:46 --------- d-----w c:\program files\Common Files\Adobe
2008-10-12 21:08 --------- d-----w c:\program files\Voxengo
2008-10-10 07:59 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle
2008-10-09 12:20 --------- d-----w c:\program files\VOB
2008-10-09 12:17 --------- d-----w c:\program files\Steinberg
2008-10-09 10:27 --------- d-----w c:\program files\ESET
2008-10-09 10:07 --------- d-----w c:\program files\Absolute MP3 Splitter
2008-10-05 12:21 --------- d-----w c:\program files\Rescue Pro
2008-09-29 04:22 --------- d-----w c:\documents and settings\All Users\Application Data\QuickTime
2008-09-29 04:21 --------- d-----w c:\program files\CyberLink
2008-09-11 03:34 --------- d-----w c:\program files\Kelk 2000
2008-09-11 03:33 --------- d-----w c:\program files\DAP
2008-09-11 03:33 --------- d-----w c:\program files\ClocX
2008-09-09 00:39 --------- d-----w c:\program files\Photodex Presenter
2008-09-09 00:39 --------- d-----w c:\program files\Photodex
2008-09-09 00:39 --------- d-----w c:\documents and settings\Administrator\Application Data\Netscape
2008-09-09 00:38 --------- d-----w c:\documents and settings\Administrator\Application Data\Photodex
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [05/08/2008 01:26 AM 68856]
"Math16"="c:\docume~1\ADMINI~1\APPLIC~1\knobthe\Chin Fast.exe" [11/06/2008 04:40 PM 660847]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [05/06/2008 08:47 PM 77824]
"pdfFactory Pro Dispatcher v2"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [11/10/2003 11:06 PM 385024]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [05/09/2008 04:27 PM 185896]
"StormCodec_Helper"="c:\program files\Ringz Studio\Storm Codec\StormSet.exe" [11/07/2008 12:22 AM 251297]
"1 mags 16 more"="c:\documents and settings\All Users\Application Data\Admin Inter 1 Mags\locks meal.exe" [11/07/2008 12:21 AM 899439]
"SoundMan"="SOUNDMAN.EXE" [11/11/2005 09:07 AM 90112 c:\windows\SOUNDMAN.EXE]
"VTTimer"="VTTimer.exe" [03/07/2005 10:33 PM 53248 c:\windows\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [03/11/2005 12:33 PM 147456 c:\windows\system32\VTTrayp.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-05-06 267119]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= DivXa32.acm
"vidc.vp31"= vp31vfw.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
--a------ 11/07/2008 12:14 AM 3209583 c:\program files\DAP\DAP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedBitVideoAccelerator]
--a------ 11/07/2008 12:14 AM 2886111 c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\SpeedBit Video Accelerator\\VideoAccelerator.exe"=
"c:\\Program Files\\SpeedBit Video Accelerator\\VideoAcceleratorEngine.exe"=
R1 Asapi;Asapi;c:\windows\system32\drivers\Asapi.sys [04/17/2002 08:27 PM 11264]
R2 ASPIXNT;ASPIXNT;c:\windows\system32\drivers\ASPIXNT.sys [06/03/2008 11:41 PM 6336]
R2 sbbotdi;sbbotdi;c:\progra~1\SPEEDB~1\sbbotdi.sys [05/06/2008 09:13 PM 35584]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe [05/06/2008 09:13 PM 280184]
S0 NeroCdNt;NeroCdNt;c:\windows\system32\drivers\NeroCdNt.sys [11/04/2008 12:23 AM 13344]
S3 SetupNTGLM7X;SetupNTGLM7X;E:\NTGLM7X.sys [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0181f5ba-290b-11dd-97e2-0016ec42f4d1}]
\Shell\AutoRun\command - F:\y82td3td.com
\Shell\explore\Command - F:\y82td3td.com
\Shell\open\Command - F:\y82td3td.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{41999132-1bb7-11dd-97c1-0016ec42f4d1}]
\Shell\AutoRun\command - F:\y82td3td.com
\Shell\explore\Command - F:\y82td3td.com
\Shell\open\Command - F:\y82td3td.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{429b5cfb-6087-11dd-987b-0016ec42f4d1}]
\Shell\AutoRun\command - F:\y82td3td.com
\Shell\explore\Command - F:\y82td3td.com
\Shell\open\Command - F:\y82td3td.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{49d19428-a418-11dd-98f3-0016ec42f4d1}]
\Shell\AutoRun\command - g2pfnid.com
\Shell\explore\Command - g2pfnid.com
\Shell\open\Command - g2pfnid.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57d40ef8-5057-11dd-982c-0016ec42f4d1}]
\Shell\AutoRun\command - F:\y82td3td.com
\Shell\explore\Command - F:\y82td3td.com
\Shell\open\Command - F:\y82td3td.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{78ecb35a-92de-11dd-98c3-fdd5eddc84ff}]
\Shell\AutoRun\command - G:\y82td3td.com
\Shell\explore\Command - G:\y82td3td.com
\Shell\open\Command - G:\y82td3td.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8fee98c2-2b2f-11dd-97e5-0016ec42f4d1}]
\Shell\AutoRun\command - qa8sywva.cmd
\Shell\explore\Command - qa8sywva.cmd
\Shell\open\Command - qa8sywva.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8fee98c3-2b2f-11dd-97e5-0016ec42f4d1}]
\Shell\AutoRun\command - F:\y82td3td.com
\Shell\explore\Command - F:\y82td3td.com
\Shell\open\Command - F:\y82td3td.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5f97ac5-a139-11dd-98e5-0016ec42f4d1}]
\Shell\AutoRun\command - F:\y82td3td.com
\Shell\explore\Command - F:\y82td3td.com
\Shell\open\Command - F:\y82td3td.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b649b57a-753f-11dd-988c-0016ec42f4d1}]
\Shell\AutoRun\command - F:\y82td3td.com
\Shell\explore\Command - F:\y82td3td.com
\Shell\open\Command - F:\y82td3td.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ba495126-9911-11dd-98d1-b2c0bf439d9f}]
\Shell\AutoRun\command - F:\y82td3td.com
\Shell\explore\Command - F:\y82td3td.com
\Shell\open\Command - F:\y82td3td.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be785b66-921c-11dd-98be-9550fd932db6}]
\Shell\AutoRun\command - F:\y82td3td.com
\Shell\explore\Command - F:\y82td3td.com
\Shell\open\Command - F:\y82td3td.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d2e63916-2b15-11dd-97e3-0016ec42f4d1}]
\Shell\AutoRun\command - F:\y82td3td.com
\Shell\explore\Command - F:\y82td3td.com
\Shell\open\Command - F:\y82td3td.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d963a24f-51a3-11dd-982f-0016ec42f4d1}]
\Shell\AutoRun\command - F:\t1ypkh.exe
\Shell\explore\Command - F:\t1ypkh.exe
\Shell\open\Command - F:\t1ypkh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ec2e0134-4309-11dd-9806-0016ec42f4d1}]
\Shell\AutoRun\command - F:\y82td3td.com
\Shell\explore\Command - F:\y82td3td.com
\Shell\open\Command - F:\y82td3td.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7058b4e-661b-11dd-9886-0016ec42f4d1}]
\Shell\AutoRun\command - F:\u2.cmd
\Shell\explore\Command - F:\u2.cmd
\Shell\open\Command - F:\u2.cmd
.
s of the 'Scheduled Tasks' folder
2008-11-07 c:\windows\Tasks\AF0D08AC918ABCAC.job
- c:\docume~1\admini~1\applic~1\knobthe\LogoHoleDraw.exe [11/06/2008 04:40 PM]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-egui - c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.raddadi.com/
R1 -: HKCU-Internet Settings,ProxyServer = https=jn;hijj89uj9ji9j:5454;hijj89uj9ji9j
O18 -: Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
O18 -: Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-07 16:32:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Crypserv.exe
c:\documents and settings\tazebama.dl_
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Photodex\ProShowGold\scsiaccess.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
.
**************************************************************************
.
Completion time: 11/07/2008 16:35:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-07 13:35:52
Pre-Run: 13,794,127,872 bytes free
Post-Run: 17,784,643,584 bytes free
253