Microsoft Windows XP Home Edition 5.1.2600.3.1256.1.1025.18.472 [GMT 3:00]
Running from: c:\documents and settings\Owner\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Application Data\.#
c:\windows\system32\Bifrost
c:\windows\system32\Bifrost\klog.dat
c:\windows\system32\MabryObj.dll
.
((((((((((((((((((((((((( Files Created from 2008-10-14 to 2008-11-14 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-14 11:26 --------- d-----w c:\program files\Common Files\Akamai
2008-11-14 11:15 32 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-14 11:15 32 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-14 11:15 32 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-14 11:15 32 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-14 11:13 --------- d---a-w c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2008-11-14 11:12 --------- d-----w c:\documents and settings\Owner\Application Data\DMCache
2008-11-14 07:58 --------- d-----w c:\program files\IEPro
2008-11-14 07:56 --------- d-----w c:\documents and settings\Owner\Application Data\IDM
2008-11-13 21:15 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\f-secure
2008-11-13 21:14 --------- d-----w c:\documents and settings\Owner\Application Data\F-Secure
2008-11-13 15:38 --------- d-----w c:\program files\Common Files\BitDefender
2008-11-13 15:10 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\fssg
2008-11-12 20:27 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2008-11-12 20:26 --------- d-----w c:\program files\MSXML 4.0
2008-11-12 20:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\DriverScanner
2008-11-12 20:10 --------- dc-h--w c:\documents and settings\All Users.WINDOWS\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2008-11-12 19:55 --------- d-----w c:\documents and settings\Owner\Application Data\Uniblue
2008-11-11 20:24 --------- d-----w c:\program files\Brave Dwarves 2
2008-11-11 15:27 --------- d-----w c:\program files\Realtek AC97
2008-11-11 15:23 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-11 15:21 --------- d-----w c:\program files\Intel
2008-11-11 15:21 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-11 13:51 --------- d-----w c:\program files\ma-config.com
2008-11-11 13:51 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\ma-config.com
2008-11-08 17:31 --------- d-----w c:\documents and settings\Owner\Application Data\cafe
2008-11-07 17:46 --------- d-----w c:\program files\3Com
2008-11-07 15:34 --------- d-----w c:\documents and settings\Owner\Application Data\Skype
2008-11-04 18:14 --------- d-----w c:\program files\AutorunRemover
2008-11-04 10:02 --------- d-----w c:\program files\Jufsoft
2008-11-03 19:02 --------- d-----w c:\program files\cddr
2008-11-03 18:44 --------- d-----w c:\documents and settings\Owner\Application Data\InfinaDyne
2008-11-03 18:41 --------- d-----w c:\program files\InfinaDyne
2008-11-03 10:05 --------- d-----w c:\program files\الدليل2
2008-11-03 09:42 73,216 ----a-w c:\windows\ST6UNST.EXE
2008-11-03 09:42 249,856 ------w c:\windows\Setup1.exe
2008-11-01 19:02 --------- d-----w c:\program files\NCC Education
2008-10-31 13:06 --------- d-----w c:\program files\Uniblue
2008-10-31 11:23 82,380 ----a-w c:\windows\system32\drivers\AFS2K.SYS
2008-10-28 10:23 --------- d-----w c:\program files\TuneUp Utilities 2008
2008-10-27 19:06 --------- d-----w c:\documents and settings\Owner\Application Data\Kelpiesoft Food File
2008-10-27 19:05 --------- d-----w c:\program files\Food File
2008-10-27 14:39 --------- dc-h--w c:\documents and settings\All Users.WINDOWS\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 06:56 --------- d-----w c:\program files\Folder Lock
2008-10-24 06:05 --------- d-----w c:\program files\cafe
2008-10-24 06:05 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\cafe
2008-10-23 10:11 --------- d-----w c:\documents and settings\Owner\Application Data\StoneLoopsRE
2008-10-19 08:30 --------- d-----w c:\program files\Google
2008-10-18 23:59 --------- d-----w c:\program files\Smarty Uninstaller Pro
2008-10-18 23:17 --------- d-----w c:\program files\RealArcade
2008-10-18 23:15 --------- d-----w c:\documents and settings\Owner\Application Data\Eyeblaster
2008-10-16 01:04 --------- d-----w c:\program files\Xilisoft
2008-10-16 01:04 --------- d-----w c:\program files\QuickTime
2008-10-15 21:37 --------- d-----w c:\program files\GVR
2008-10-15 21:27 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-10-15 21:27 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-10-15 03:04 --------- d-----w c:\program files\Picasa2
2008-10-14 21:22 --------- d-----w c:\program files\Mobiola Web Camera 2 for S60 2nd Edition
2008-10-14 00:27 --------- dc-h--w c:\documents and settings\All Users.WINDOWS\Application Data\{8CC5CF4A-124E-41BA-B58C-A41F05BE09CC}
2008-10-13 23:09 --------- d-----w c:\program files\Amadis Software
2008-10-13 22:56 203,776 ----a-w c:\windows\system32\clrviddc.dll
2008-10-13 20:07 --------- d-----w c:\program files\CreativePainter
2008-10-13 07:27 --------- d-----w c:\program files\Folder Lock 6
2008-10-13 06:57 --------- d-----w c:\documents and settings\Owner\Application Data\skypePM
2008-10-13 06:55 --------- d-----w c:\program files\Skype
2008-10-13 06:55 --------- d-----w c:\program files\Common Files\Skype
2008-10-13 06:55 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Skype
2008-10-12 12:37 --------- d-----w c:\program files\Scorpio Software
2008-10-12 12:37 --------- d-----w c:\program files\Common Files\scosoft.com
2008-10-12 12:21 --------- d-----w c:\program files\Hotspot Shield
2008-10-11 16:26 --------- d-----w c:\documents and settings\Owner\Application Data\Thinstall
2008-10-11 11:49 --------- d-----w c:\program files\Trojan Remover
2008-10-10 17:56 --------- d-----w c:\program files\Yahoo!
2008-10-10 16:13 --------- dc-h--w c:\documents and settings\All Users.WINDOWS\Application Data\{8A09CD83-59E1-4DB1-AAFC-E25174FC6706}
2008-10-10 10:52 --------- d-----w c:\program files\Java
2008-10-09 00:05 --------- d-----w c:\program files\Realtek Sound Manager
2008-10-09 00:05 --------- d-----w c:\program files\AvRack
2008-10-08 21:02 --------- d-----w c:\documents and settings\Owner\Application Data\PC Suite
2008-10-08 21:01 --------- d-----w c:\documents and settings\Owner\Application Data\Nokia
2008-10-08 20:46 --------- d-----w c:\program files\IconTweaker
2008-10-08 20:46 --------- d-----w c:\documents and settings\Owner\Application Data\IconTweaker
2008-10-08 20:31 --------- d-----w c:\program files\Custom Icons(2)
2008-10-07 21:29 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\IconTweaker
2008-10-07 19:06 72,066 ----a-w c:\windows\BricoPackUninst.cmd
2008-10-07 19:06 5,259 ----a-w c:\windows\BricoPackFoldersDelete.cmd
2008-10-07 00:13 --------- d-----w c:\program files\Common Files\PCSuite
2008-10-07 00:13 --------- d-----w c:\program files\Common Files\Nokia
2008-10-07 00:10 --------- d-----w c:\program files\PC Connectivity Solution
2008-10-07 00:07 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Installations
2008-10-07 00:00 --------- d-----w c:\program files\Nokia
2008-10-04 00:32 --------- d-----w c:\program files\GameTop.com
2008-10-03 03:13 --------- d-----w c:\program files\Chicken Invaders 3
2008-09-30 13:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-29 14:44 --------- d-----w c:\program files\Windows Live Safety Center
2008-09-28 21:46 --------- dc-h--w c:\documents and settings\All Users.WINDOWS\Application Data\{96F5B506-0F68-4EDB-AD12-CF915081579C}
2008-09-28 21:31 --------- d-----w c:\program files\Stardock
2008-09-24 07:40 4,122,368 ----a-r c:\windows\system32\drivers\alcxwdm.sys
2008-09-16 00:59 --------- d-----w c:\program files\ReflexiveArcade
2008-09-16 00:59 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\InterAction studios
2008-07-08 02:27 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008070820080709\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [07/26/2008 02:31 PM 5724184]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
--a------ 08/11/2008 08:31 AM 1124352 c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
"NCLaunch"=c:\windows\NCLAUNCH.EXe
"Picasa Media Detector"=c:\program files\Picasa2\PicasaMediaDetector.exe
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"IDMan"=c:\program files\Internet Download Manager\IDMan.exe /onboot
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMan"=SOUNDMAN.EXE
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"IgfxTray"=c:\windows\system32\igfxtray.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"NeroFilterCheck"=c:\program files\Common Files\Nero\Lib\NeroCheck.exe
"Custom Skin Clock"=c:\program files\Custom Skin Clock\Clock.exe
"HPDJ Taskbar Utility"=c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\All Users.WINDOWS\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
"c:\\Program Files\\IEPro\\MiniDM.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9420:TCP"= 9420:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R2 Akamai;Akamai;c:\windows\System32\svchost.exe [04/14/2008 07:00 PM 14336]
R2 Uniblue DiskRescue;Uniblue DiskRescue;c:\program files\Uniblue\DiskRescue\UBDiskRescueSrv.exe [09/10/2008 06:22 PM 229648]
R2 UxTuneUp;TuneUp Theme Extension;c:\windows\System32\svchost.exe [04/14/2008 07:00 PM 14336]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [04/30/2008 06:06 PM 24592]
R3 TViewPCI;TView Gold PCI;c:\windows\system32\Drivers\TViewPCI.sys [11/04/2003 11:31 AM 36960]
S2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [ ]
S3 BTCAMDRV;Mobiola Web Camera driver;c:\windows\system32\DRIVERS\BTCamDrv.sys [06/02/2005 06:19 PM 228352]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;c:\docume~1\Owner\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys [ ]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [11/02/2008 03:29 PM 195752]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;c:\windows\System32\TuneUpDefragService.exe [08/13/2008 05:14 PM 355584]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
s of the 'Scheduled Tasks' folder
2008-11-14 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [06/20/2008 09:09 AM]
2008-11-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [08/29/2006 02:21 PM]
2008-10-31 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp psc 1100 series#1225456175.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [04/06/2003 12:52 AM]
2008-10-10 c:\windows\Tasks\Uniblue DiskRescue 2009.job
- c:\program files\Uniblue\DiskRescue\UBDiskRescue.exe [09/10/2008 06:22 PM]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\xnle9b79.default\
FF -: plugin - c:\program files\ma-config.com\nphardwaredetection.dll
FF -: plugin - c:\program files\Picasa2\npPicasa2.dll
.
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-14 14:25:31
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\sccfg.sys 20 bytes
**************************************************************************
.
Completion time: 11/14/2008 14:28:36
ComboFix-quarantined-files.txt 2008-11-14 11:27:33
ComboFix2.txt 2008-10-07 19:56:32
Pre-Run: 21,503,942,656 bytes free
Post-Run: 22,144,888,832 bytes free
229 --- E O F --- 2008-11-12 20:27:06