تفضل هذا التقرير..
ComboFix 08-11-20.02 - owner 2008-11-21 12:35:02.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.558 [GMT -8:00]
Running from: c:\documents and settings\owner\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-10-21 to 2008-11-21 )))))))))))))))))))))))))))))))
.
2008-11-21 04:04 . 2008-11-21 04:04 230 --a------ c:\windows\system32\spupdsvc.inf
2008-11-21 03:50 . 2008-11-21 03:50 <DIR> d-------- c:\program files\Kaspersky Lab
2008-11-21 03:50 . 2008-11-21 11:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-21 03:50 . 2008-11-21 12:38 942,624 --ahs---- c:\windows\system32\drivers\fidbox.dat
2008-11-21 03:50 . 2008-11-21 04:19 96,976 --a------ c:\windows\system32\drivers\klin.dat
2008-11-21 03:50 . 2008-11-21 04:19 87,855 --a------ c:\windows\system32\drivers\klick.dat
2008-11-21 03:50 . 2008-11-21 12:37 14,696 --ahs---- c:\windows\system32\drivers\fidbox.idx
2008-11-21 03:50 . 2008-11-21 12:37 8,480 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2008-11-21 03:50 . 2008-11-21 12:37 1,820 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2008-11-21 03:46 . 2008-11-21 03:46 <DIR> d-------- c:\program files\IEPro
2008-11-21 03:46 . 2008-11-21 03:46 <DIR> d-------- c:\documents and settings\owner\Application Data\IEPro
2008-11-21 03:38 . 2008-11-21 03:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-21 02:36 . 2008-10-03 09:41 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-11-21 02:36 . 2007-04-17 01:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-11-21 02:36 . 2007-03-07 21:10 991,232 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-11-21 02:36 . 2008-08-25 23:24 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-11-21 02:36 . 2008-08-25 23:24 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-11-21 02:36 . 2008-08-25 23:24 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-11-21 02:36 . 2008-08-25 23:24 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-11-21 02:36 . 2008-08-25 23:24 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-11-21 02:36 . 2008-08-25 00:38 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-11-21 01:46 . 2008-11-21 01:46 <DIR> d-------- c:\program files\x264
2008-11-21 01:46 . 2008-11-21 01:46 580,114 --a------ c:\windows\system32\x264vfw.dll
2008-11-21 01:25 . 2008-11-21 03:19 <DIR> d-------- c:\program files\NOS
2008-11-21 01:25 . 2008-11-21 01:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
2008-11-21 01:22 . 2008-11-21 01:22 <DIR> d-------- c:\program files\fileflyer
2008-11-21 01:22 . 2008-11-21 01:22 <DIR> d-------- c:\program files\Conduit
2008-11-21 01:21 . 2008-11-21 12:37 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-11-21 01:20 . 2008-11-21 01:20 <DIR> d-------- c:\program files\uTorrent
2008-11-21 01:20 . 2008-11-21 01:20 <DIR> d-------- c:\program files\Google
2008-11-21 01:20 . 2008-11-21 03:09 <DIR> d-------- c:\program files\DAP
2008-11-21 01:20 . 2008-11-21 02:44 <DIR> d-------- c:\documents and settings\owner\Application Data\uTorrent
2008-11-21 01:20 . 2008-11-21 01:20 479,298 --a------ c:\windows\system32\wbocx.ocx
2008-11-21 01:20 . 2008-11-21 01:20 172,032 --a------ c:\windows\system32\AniGIF.ocx
2008-11-21 01:20 . 2008-11-21 01:20 50,688 --a------ c:\windows\system32\wbhelp2.dll
2008-11-21 00:38 . 2008-11-21 00:38 <DIR> d-------- c:\documents and settings\owner\Application Data\Thinstall
2008-11-21 00:29 . 2008-11-21 00:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-11-21 00:17 . 2008-11-21 00:17 <DIR> d-------- c:\program files\Messenger Plus! Live
2008-11-21 00:17 . 2008-11-21 00:17 <DIR> d-------- c:\program files\Circle Developement
2008-11-21 00:15 . 2008-11-21 00:35 <DIR> d-------- c:\documents and settings\owner\Contacts
2008-11-21 00:14 . 2008-11-21 00:14 <DIR> d----c--- c:\windows\system32\DRVSTORE
2008-11-21 00:14 . 2008-11-21 00:15 <DIR> d-------- c:\program files\Windows Live Toolbar
2008-11-21 00:14 . 2008-11-21 00:14 <DIR> d-------- c:\program files\Windows Live Favorites
2008-11-21 00:11 . 2008-11-21 01:56 <DIR> d-------- c:\documents and settings\owner\Application Data\Aegisub
2008-11-21 00:06 . 2008-11-21 00:13 <DIR> d--hsc--- c:\program files\Common Files\WindowsLiveInstaller
2008-11-21 00:05 . 2008-11-21 00:14 <DIR> d-------- c:\program files\Windows Live
2008-11-21 00:05 . 2008-11-21 00:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-20 23:48 . 2008-10-16 14:09 43,544 --a------ c:\windows\system32\wups2.dll
2008-11-20 23:48 . 2008-10-16 14:09 31,768 --a------ c:\windows\system32\wucltui.dll.mui
2008-11-20 23:48 . 2008-10-16 14:07 23,576 --a------ c:\windows\system32\wuaucpl.cpl.mui
2008-11-20 23:48 . 2008-10-16 14:07 23,576 --a------ c:\windows\system32\wuapi.dll.mui
2008-11-20 23:48 . 2008-10-16 14:07 18,456 --a------ c:\windows\system32\wuaueng.dll.mui
2008-11-20 23:47 . 2001-08-23 07:00 68,608 --a------ c:\windows\system32\plugin.ocx
2008-11-20 23:47 . 2001-08-23 07:00 68,608 --a------ c:\windows\system32\dllcache\plugin.ocx
2008-11-20 23:46 . 2008-11-21 02:39 <DIR> d--h----- c:\windows\$hf_mig$
2008-11-20 23:37 . 2008-11-20 23:37 <DIR> d--hs---- c:\documents and settings\owner\UserData
2008-11-20 23:26 . 2004-08-03 23:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-11-20 22:02 . 2008-11-20 22:02 <DIR> d-------- c:\program files\Yahoo!
2008-11-20 22:02 . 2008-11-20 22:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-21 12:20 112,144 ----a-w c:\windows\system32\drivers\kl1.sys
2008-11-21 05:58 155,995 ----a-w c:\windows\java\Packages\61ZTJ7D3.ZIP
2008-11-21 05:58 --------- d-----w c:\program files\Opera
2008-11-21 05:57 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-21 05:56 --------- d-----w c:\program files\Total Video Converter
2008-11-21 05:55 --------- d-----w c:\program files\Common Files\Ahead
2008-11-21 05:55 --------- d-----w c:\documents and settings\owner\Application Data\Ahead
2008-11-21 05:54 --------- d-----w c:\program files\Nero
2008-11-21 05:54 --------- d-----w c:\program files\Common Files\xing shared
2008-11-21 05:54 --------- d-----w c:\program files\Common Files\Real
2008-11-21 05:52 --------- d-----w c:\program files\Real
2008-11-21 05:52 --------- d-----w c:\documents and settings\owner\Application Data\BSplayer PRO
2008-11-21 05:51 47,104 ------w c:\windows\AKDeInstall.exe
2008-11-21 05:51 --------- d-----w c:\program files\mpegable
2008-11-21 05:51 --------- d-----w c:\program files\GRETECH
2008-11-21 05:48 --------- d-----w c:\program files\Webteh
2008-11-21 05:45 --------- d-----w c:\program files\Microsoft.NET
2008-11-21 05:45 --------- d-----w c:\program files\Microsoft ActiveSync
2008-11-21 05:31 --------- d-----w c:\program files\CONEXANT
2008-11-21 05:29 16,608 ----a-w c:\windows\gdrv.sys
2008-11-21 05:29 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-21 05:29 --------- d-----w c:\program files\Realtek
2008-11-21 05:29 --------- d-----w c:\documents and settings\owner\Application Data\InstallShield
2008-11-21 05:27 315,392 ----a-w c:\windows\HideWin.exe
2008-11-21 05:27 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-21 05:25 --------- d-----w c:\program files\Intel
2008-11-21 05:09 --------- d-----w c:\program files\microsoft frontpage
2008-11-21 09:20 251,392 ----a-w c:\program files\opera\program\plugins\dapop.dll
.
((((((((((((((((((((((((((((( snapshot@2008-11-21_ 3.33.09.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-05 04:16:46 1,887,080 ----a-w c:\windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
+ 2005-10-21 04:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2007-08-14 02:39:20 71,680 ----a-w c:\windows\system32\admparse.dll
+ 2004-08-03 22:56:42 61,440 ----a-w c:\windows\system32\admparse.dll
- 2008-08-26 07:24:28 124,928 ----a-w c:\windows\system32\advpack.dll
+ 2004-08-03 22:56:42 99,840 ----a-w c:\windows\system32\advpack.dll
- 2006-09-23 21:12:50 1,022,976 ----a-w c:\windows\system32\browseui.dll
+ 2004-08-03 22:56:42 1,016,832 ----a-w c:\windows\system32\browseui.dll
- 2007-08-14 02:42:54 17,408 ----a-w c:\windows\system32\corpol.dll
+ 2004-08-03 22:56:42 35,328 ----a-w c:\windows\system32\corpol.dll
- 2007-08-14 02:39:20 71,680 -c--a-w c:\windows\system32\dllcache\admparse.dll
+ 2004-08-03 22:56:42 61,440 -c--a-w c:\windows\system32\dllcache\admparse.dll
- 2008-08-26 07:24:28 124,928 -c--a-w c:\windows\system32\dllcache\advpack.dll
+ 2004-08-03 22:56:42 99,840 -c--a-w c:\windows\system32\dllcache\advpack.dll
- 2006-09-23 21:12:50 1,022,976 -c--a-w c:\windows\system32\dllcache\browseui.dll
+ 2004-08-03 22:56:42 1,016,832 -c--a-w c:\windows\system32\dllcache\browseui.dll
- 2007-08-14 02:42:54 17,408 -c--a-w c:\windows\system32\dllcache\corpol.dll
+ 2004-08-03 22:56:42 35,328 -c--a-w c:\windows\system32\dllcache\corpol.dll
- 2007-08-14 02:54:10 33,792 -c--a-w c:\windows\system32\dllcache\custsat.dll
+ 2004-08-03 22:56:42 28,672 -c--a-w c:\windows\system32\dllcache\custsat.dll
- 2008-08-26 07:24:28 347,136 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
+ 2004-08-03 22:56:44 357,888 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-03 22:56:44 201,728 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
- 2008-08-26 07:24:28 133,120 -c--a-w c:\windows\system32\dllcache\extmgr.dll
+ 2004-08-03 22:56:44 55,808 -c--a-w c:\windows\system32\dllcache\extmgr.dll
- 2007-08-14 02:18:02 60,416 -c--a-w c:\windows\system32\dllcache\hmmapi.dll
+ 2004-08-03 22:56:44 38,912 -c--a-w c:\windows\system32\dllcache\hmmapi.dll
- 2008-08-25 08:37:59 70,656 -c--a-w c:\windows\system32\dllcache\ie4uinit.exe
+ 2004-08-03 22:56:52 34,304 -c--a-w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 -c--a-w c:\windows\system32\dllcache\ieakeng.dll
+ 2004-08-03 22:56:44 139,264 -c--a-w c:\windows\system32\dllcache\ieakeng.dll
- 2008-08-26 07:24:28 230,400 -c--a-w c:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-03 22:56:44 216,576 -c--a-w c:\windows\system32\dllcache\ieaksie.dll
- 2008-08-23 05:54:51 161,792 -c--a-w c:\windows\system32\dllcache\ieakui.dll
+ 2001-08-23 15:00:00 221,184 -c--a-w c:\windows\system32\dllcache\ieakui.dll
- 2008-08-26 07:24:29 384,512 -c--a-w c:\windows\system32\dllcache\iedkcs32.dll
+ 2004-08-03 22:56:44 323,584 -c--a-w c:\windows\system32\dllcache\iedkcs32.dll
- 2007-08-14 02:44:02 69,120 -c--a-w c:\windows\system32\dllcache\iedw.exe
+ 2004-08-03 22:56:52 18,432 -c--a-w c:\windows\system32\dllcache\iedw.exe
- 2007-08-14 02:45:18 78,336 -c--a-w c:\windows\system32\dllcache\ieencode.dll
+ 2004-08-03 22:56:44 81,920 -c--a-w c:\windows\system32\dllcache\ieencode.dll
- 2007-08-14 02:54:10 191,488 -c--a-w c:\windows\system32\dllcache\iepeers.dll
+ 2004-08-03 22:56:44 249,344 -c--a-w c:\windows\system32\dllcache\iepeers.dll
- 2008-08-26 07:24:29 44,544 -c--a-w c:\windows\system32\dllcache\iernonce.dll
+ 2004-08-03 22:56:44 48,640 -c--a-w c:\windows\system32\dllcache\iernonce.dll
- 2007-08-14 02:39:12 55,296 -c--a-w c:\windows\system32\dllcache\iesetup.dll
+ 2004-08-03 22:56:44 62,976 -c--a-w c:\windows\system32\dllcache\iesetup.dll
- 2008-08-23 05:56:15 635,848 -c--a-w c:\windows\system32\dllcache\iexplore.exe
+ 2004-08-03 22:56:52 93,184 -c--a-w c:\windows\system32\dllcache\iexplore.exe
- 2007-08-14 02:36:06 36,352 -c--a-w c:\windows\system32\dllcache\imgutil.dll
+ 2004-08-03 22:56:44 35,840 -c--a-w c:\windows\system32\dllcache\imgutil.dll
- 2007-08-14 02:39:02 92,672 -c--a-w c:\windows\system32\dllcache\inseng.dll
+ 2004-08-03 22:56:44 96,256 -c--a-w c:\windows\system32\dllcache\inseng.dll
- 2007-08-14 02:38:04 491,520 -c--a-w c:\windows\system32\dllcache\jscript.dll
+ 2004-08-03 22:56:44 450,560 -c--a-w c:\windows\system32\dllcache\jscript.dll
- 2008-08-26 07:24:30 27,648 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-03 22:56:44 15,872 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
- 2007-08-14 02:44:18 40,960 -c--a-w c:\windows\system32\dllcache\licmgr10.dll
+ 2004-08-03 22:56:44 22,016 -c--a-w c:\windows\system32\dllcache\licmgr10.dll
- 2007-08-14 02:32:30 45,568 -c--a-w c:\windows\system32\dllcache\mshta.exe
+ 2004-08-03 22:56:54 29,184 -c--a-w c:\windows\system32\dllcache\mshta.exe
- 2008-08-27 21:54:32 3,593,216 -c--a-w c:\windows\system32\dllcache\mshtml.dll
+ 2004-08-03 22:56:44 3,003,392 -c--a-w c:\windows\system32\dllcache\mshtml.dll
- 2008-08-26 07:24:30 477,696 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
+ 2004-08-03 22:56:44 448,512 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
- 2007-08-14 02:01:12 48,128 -c--a-w c:\windows\system32\dllcache\mshtmler.dll
+ 2004-08-03 22:56:16 56,832 -c--a-w c:\windows\system32\dllcache\mshtmler.dll
- 2007-08-14 02:54:10 156,160 -c--a-w c:\windows\system32\dllcache\msls31.dll
+ 2001-08-23 15:00:00 146,432 -c--a-w c:\windows\system32\dllcache\msls31.dll
- 2008-08-26 07:24:30 193,024 -c--a-w c:\windows\system32\dllcache\msrating.dll
+ 2004-08-03 22:56:44 146,432 -c--a-w c:\windows\system32\dllcache\msrating.dll
- 2008-08-26 07:24:30 671,232 -c--a-w c:\windows\system32\dllcache\mstime.dll
+ 2004-08-03 22:56:44 530,432 -c--a-w c:\windows\system32\dllcache\mstime.dll
- 2008-08-26 07:24:30 102,912 -c--a-w c:\windows\system32\dllcache\occache.dll
+ 2004-08-03 22:56:46 96,256 -c--a-w c:\windows\system32\dllcache\occache.dll
- 2008-08-26 07:24:30 44,544 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
+ 2004-08-03 22:56:46 39,424 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
- 2006-09-23 21:12:50 1,497,088 -c--a-w c:\windows\system32\dllcache\shdocvw.dll
+ 2004-08-03 22:56:46 1,483,264 -c--a-w c:\windows\system32\dllcache\shdocvw.dll
- 2006-09-23 21:12:50 474,112 -c--a-w c:\windows\system32\dllcache\shlwapi.dll
+ 2004-08-03 22:56:46 473,600 -c--a-w c:\windows\system32\dllcache\shlwapi.dll
- 2008-08-26 07:24:30 105,984 -c--a-w c:\windows\system32\dllcache\url.dll
+ 2004-08-03 22:56:48 37,888 -c--a-w c:\windows\system32\dllcache\url.dll
- 2008-08-26 07:24:31 1,159,680 -c--a-w c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-03 22:56:48 601,088 -c--a-w c:\windows\system32\dllcache\urlmon.dll
- 2007-08-14 02:54:10 413,696 -c--a-w c:\windows\system32\dllcache\vbscript.dll
+ 2004-08-03 22:56:48 417,792 -c--a-w c:\windows\system32\dllcache\vbscript.dll
- 2007-08-14 02:54:10 765,952 -c--a-w c:\windows\system32\dllcache\VGX.dll
+ 2004-08-03 22:56:48 848,384 -c--a-w c:\windows\system32\dllcache\vgx.dll
- 2008-08-26 07:24:31 233,472 -c--a-w c:\windows\system32\dllcache\webcheck.dll
+ 2004-08-03 22:56:48 276,480 -c--a-w c:\windows\system32\dllcache\webcheck.dll
- 2008-08-26 07:24:31 826,368 -c--a-w c:\windows\system32\dllcache\wininet.dll
+ 2004-08-03 22:56:48 656,384 -c--a-w c:\windows\system32\dllcache\wininet.dll
+ 2007-12-29 03:51:04 195,344 ----a-w c:\windows\system32\drivers\klif.sys
+ 2007-12-13 21:28:40 24,592 ----a-w c:\windows\system32\drivers\klim5.sys
+ 2008-02-09 02:35:42 23,604 ----a-w c:\windows\system32\drivers\klopp.dat
- 2008-08-26 07:24:28 347,136 ----a-w c:\windows\system32\dxtmsft.dll
+ 2004-08-03 22:56:44 357,888 ----a-w c:\windows\system32\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 ----a-w c:\windows\system32\dxtrans.dll
+ 2004-08-03 22:56:44 201,728 ----a-w c:\windows\system32\dxtrans.dll
- 2008-08-26 07:24:28 133,120 ----a-w c:\windows\system32\extmgr.dll
+ 2004-08-03 22:56:44 55,808 ----a-w c:\windows\system32\extmgr.dll
- 2008-08-25 08:37:59 70,656 ----a-w c:\windows\system32\ie4uinit.exe
+ 2004-08-03 22:56:52 34,304 ----a-w c:\windows\system32\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 ----a-w c:\windows\system32\ieakeng.dll
+ 2004-08-03 22:56:44 139,264 ----a-w c:\windows\system32\ieakeng.dll
- 2008-08-26 07:24:28 230,400 ----a-w c:\windows\system32\ieaksie.dll
+ 2004-08-03 22:56:44 216,576 ----a-w c:\windows\system32\ieaksie.dll
- 2008-08-23 05:54:51 161,792 ----a-w c:\windows\system32\ieakui.dll
+ 2001-08-23 15:00:00 221,184 ----a-w c:\windows\system32\ieakui.dll
- 2008-08-26 07:24:29 384,512 ----a-w c:\windows\system32\iedkcs32.dll
+ 2004-08-03 22:56:44 323,584 ----a-w c:\windows\system32\iedkcs32.dll
- 2007-08-14 02:45:18 78,336 ----a-w c:\windows\system32\ieencode.dll
+ 2004-08-03 22:56:44 81,920 ----a-w c:\windows\system32\ieencode.dll
- 2007-08-14 02:54:10 191,488 ----a-w c:\windows\system32\iepeers.dll
+ 2004-08-03 22:56:44 249,344 ----a-w c:\windows\system32\iepeers.dll
- 2008-08-26 07:24:29 44,544 ----a-w c:\windows\system32\iernonce.dll
+ 2004-08-03 22:56:44 48,640 ----a-w c:\windows\system32\iernonce.dll
- 2007-08-14 02:39:12 55,296 ----a-w c:\windows\system32\iesetup.dll
+ 2004-08-03 22:56:44 62,976 ----a-w c:\windows\system32\iesetup.dll
- 2007-08-14 02:36:06 36,352 ----a-w c:\windows\system32\imgutil.dll
+ 2004-08-03 22:56:44 35,840 ----a-w c:\windows\system32\imgutil.dll
- 2007-08-14 02:39:02 92,672 ----a-w c:\windows\system32\inseng.dll
+ 2004-08-03 22:56:44 96,256 ----a-w c:\windows\system32\inseng.dll
- 2007-08-14 02:38:04 491,520 ----a-w c:\windows\system32\jscript.dll
+ 2004-08-03 22:56:44 450,560 ----a-w c:\windows\system32\jscript.dll
- 2008-08-26 07:24:30 27,648 ----a-w c:\windows\system32\jsproxy.dll
+ 2004-08-03 22:56:44 15,872 ----a-w c:\windows\system32\jsproxy.dll
+ 2008-02-09 02:37:44 219,664 ----a-w c:\windows\system32\klogon.dll
- 2007-08-14 02:44:18 40,960 ----a-w c:\windows\system32\licmgr10.dll
+ 2004-08-03 22:56:44 22,016 ----a-w c:\windows\system32\licmgr10.dll
+ 2008-10-05 03:16:26 235,936 ----a-r c:\windows\system32\Macromed\Flash\FlashUtil10a.exe
+ 2008-11-21 11:37:48 89,102 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
- 2007-08-14 02:32:30 45,568 ----a-w c:\windows\system32\mshta.exe
+ 2004-08-03 22:56:54 29,184 ----a-w c:\windows\system32\mshta.exe
- 2008-08-27 21:54:32 3,593,216 ----a-w c:\windows\system32\mshtml.dll
+ 2004-08-03 22:56:44 3,003,392 ----a-w c:\windows\system32\mshtml.dll
- 2008-08-26 07:24:30 477,696 ----a-w c:\windows\system32\mshtmled.dll
+ 2004-08-03 22:56:44 448,512 ----a-w c:\windows\system32\mshtmled.dll
- 2007-08-14 02:01:12 48,128 ----a-w c:\windows\system32\mshtmler.dll
+ 2004-08-03 22:56:16 56,832 ----a-w c:\windows\system32\mshtmler.dll
- 2007-08-14 02:54:10 156,160 ----a-w c:\windows\system32\msls31.dll
+ 2001-08-23 15:00:00 146,432 ----a-w c:\windows\system32\msls31.dll
- 2008-08-26 07:24:30 193,024 ----a-w c:\windows\system32\msrating.dll
+ 2004-08-03 22:56:44 146,432 ----a-w c:\windows\system32\msrating.dll
- 2008-08-26 07:24:30 671,232 ----a-w c:\windows\system32\mstime.dll
+ 2004-08-03 22:56:44 530,432 ----a-w c:\windows\system32\mstime.dll
- 2008-08-26 07:24:30 102,912 ----a-w c:\windows\system32\occache.dll
+ 2004-08-03 22:56:46 96,256 ----a-w c:\windows\system32\occache.dll
- 2008-08-26 07:24:30 44,544 ----a-w c:\windows\system32\pngfilt.dll
+ 2004-08-03 22:56:46 39,424 ----a-w c:\windows\system32\pngfilt.dll
- 2006-09-23 21:12:50 1,497,088 ----a-w c:\windows\system32\shdocvw.dll
+ 2004-08-03 22:56:46 1,483,264 ----a-w c:\windows\system32\shdocvw.dll
- 2006-09-23 21:12:50 474,112 ----a-w c:\windows\system32\shlwapi.dll
+ 2004-08-03 22:56:46 473,600 ----a-w c:\windows\system32\shlwapi.dll
- 2008-08-26 07:24:30 105,984 ----a-w c:\windows\system32\url.dll
+ 2004-08-03 22:56:48 37,888 ----a-w c:\windows\system32\url.dll
- 2008-08-26 07:24:31 1,159,680 ----a-w c:\windows\system32\urlmon.dll
+ 2004-08-03 22:56:48 601,088 ----a-w c:\windows\system32\urlmon.dll
- 2007-08-14 02:54:10 413,696 ----a-w c:\windows\system32\vbscript.dll
+ 2004-08-03 22:56:48 417,792 ----a-w c:\windows\system32\vbscript.dll
- 2008-08-26 07:24:31 233,472 ----a-w c:\windows\system32\webcheck.dll
+ 2004-08-03 22:56:48 276,480 ----a-w c:\windows\system32\webcheck.dll
- 2008-08-26 07:24:31 826,368 ----a-w c:\windows\system32\wininet.dll
+ 2004-08-03 22:56:48 656,384 ----a-w c:\windows\system32\wininet.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{72c9b60b-f700-472c-b960-5d37c8c46db9}"= "c:\program files\fileflyer\tbfile.dll" [2008-08-20 1780248]
[HKEY_CLASSES_ROOT\clsid\{72c9b60b-f700-472c-b960-5d37c8c46db9}]
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{72c9b60b-f700-472c-b960-5d37c8c46db9}]
2008-08-20 23:03 1780248 --a------ c:\program files\fileflyer\tbfile.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{72c9b60b-f700-472c-b960-5d37c8c46db9}"= "c:\program files\fileflyer\tbfile.dll" [2008-08-20 1780248]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{72C9B60B-F700-472C-B960-5D37C8C46DB9}"= "c:\program files\fileflyer\tbfile.dll" [2008-08-20 1780248]
[HKEY_CLASSES_ROOT\clsid\{72c9b60b-f700-472c-b960-5d37c8c46db9}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-11-21 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2008-11-21 3057152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
"vidc.X264"= x264vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-10-28 16:25 94208 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
-ra------ 2005-11-27 21:52 77824 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
-ra------ 2005-11-27 21:55 118784 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
-ra------ 2005-11-27 21:55 98304 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-11-20 21:54 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-03-01 18:11 4670968 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 02:43 69632 c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2008-02-12 22:31 16857600 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IEPro\\MiniDM.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\English\\setup.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-12-13 24592]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8e0c98a-b79d-11dd-b3e6-001d7d7578a8}]
\Shell\AutoRun\command - WDSetup.exe
.
s of the 'Scheduled Tasks' folder
2008-11-21 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
.
------- Supplementary Scan -------
.
uStart Page = res://c:\program files\IEPro\IEProRs.dll/easyhome.html
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {000002a3-84fe-43f1-b958-f2c3ca804f1a} - {CD275D4E-791A-4993-9D4D-6A071EDD2709} - c:\program files\IEPro\iepro.dll
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
O16 -: Microsoft XML Parser for Java -
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-21 12:38:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-11-21 12:39:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-21 20:39:29
ComboFix2.txt 2008-11-21 11:33:24
Pre-Run: 33,838,493,696 bytes free
Post-Run: 34,349,625,344 bytes free
384