ComboFix 08-11-23.02 - Yasser Hamde 11/25/2008 1:30:25.1 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.39 [GMT -8:00]
Running from: c:\documents and settings\Yasser Hamde\My Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\recycler\_desktop.ini
e:\recycler\_desktop.ini
H:\Autorun.inf
I:\Autorun.inf
J:\Autorun.inf
K:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-10-25 to 2008-11-25 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-25 09:33 49,184 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-25 09:33 2,296 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-25 09:33 2,100,256 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-25 09:33 19,584 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-24 23:57 --------- d-----w c:\program files\Winamp Remote
2008-11-24 23:57 --------- d-----w c:\documents and settings\All Users\Application Data\OrbNetworks
2008-11-24 23:46 --------- d-----w c:\program files\Winamp
2008-11-24 23:46 --------- d-----w c:\documents and settings\Yasser Hamde\Application Data\Winamp
2008-11-24 23:41 --------- d-----w c:\program files\Common Files\xing shared
2008-11-24 23:40 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-11-24 23:40 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-11-24 23:40 --------- d-----w c:\program files\Real
2008-11-24 23:40 --------- d-----w c:\program files\Common Files\Real
2008-11-24 22:20 --------- d-----w c:\documents and settings\Yasser Hamde\Application Data\Gena01
2008-11-24 06:28 96,976 ----a-w c:\windows\system32\drivers\klin.dat
2008-11-24 03:57 --------- d-----w c:\program files\microsoft frontpage
2008-11-23 19:45 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-11-23 19:41 --------- d-----w c:\documents and settings\Yasser Hamde\Application Data\IDM
2008-11-23 19:41 --------- d-----w c:\documents and settings\Yasser Hamde\Application Data\DMCache
2008-11-23 19:40 --------- d-----w c:\program files\Internet Download Manager
2008-11-23 19:12 --------- d-----w c:\program files\Windows Live
2008-11-23 19:12 --------- d-----w c:\program files\Messenger Plus! Live
2008-11-23 19:06 87,855 ----a-w c:\windows\system32\drivers\klick.dat
2008-11-23 19:04 --------- d-----w c:\program files\Kaspersky Lab
2008-11-23 19:04 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-23 19:00 --------- d-----w c:\program files\Common Files\Adobe
2008-11-23 18:59 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-23 18:59 --------- d-----w c:\program files\MSN Messenger
2008-11-23 18:59 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-23 18:59 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-23 18:49 --------- d-----w c:\documents and settings\All Users\Application Data\PC Suite
2008-11-23 18:48 --------- d-----w c:\program files\Common Files\PCSuite
2008-11-23 18:48 --------- d-----w c:\program files\Common Files\Nokia
2008-11-23 18:48 --------- d-----w c:\documents and settings\Yasser Hamde\Application Data\Nokia
2008-11-23 18:47 --------- d-----w c:\program files\PC Connectivity Solution
2008-11-23 18:47 --------- d-----w c:\program files\Nokia
2008-11-23 18:47 --------- d-----w c:\program files\DIFX
2008-11-23 18:47 --------- d-----w c:\documents and settings\Yasser Hamde\Application Data\PC Suite
2008-11-23 18:46 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2008-11-23 18:19 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-23 18:19 --------- d-----w c:\documents and settings\Yasser Hamde\Application Data\Media Player Classic
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:21 455,296 ------w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-16 22:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 22:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 22:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 22:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 22:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 22:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 22:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 22:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 22:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-15 16:34 337,408 ----a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-03 17:41 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
2008-09-22 14:03 1,571,001 ----a-w c:\windows\system32\sisgl.dll
2008-09-22 13:47 3,473,920 ----a-w c:\windows\system32\sisgrv.dll
2008-09-22 13:47 3,473,920 ----a-w c:\windows\system32\dllcache\sisgrv.dll
2008-09-22 13:42 323,584 ----a-w c:\windows\system32\dllcache\sisgrp.sys
2008-09-22 13:39 9,728 ----a-w c:\windows\system32\SiSPIns2.dll
2008-09-22 13:38 258,048 ----a-w c:\windows\system32\SiSParse.dll
2008-09-22 13:38 172,032 ----a-w c:\windows\system32\SiSInst.dll
2008-09-22 13:38 12,288 ----a-w c:\windows\InstFunc.dll
2008-09-22 13:37 49,152 ----a-w c:\windows\system32\SiSBase.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\dllcache\win32k.sys
2008-09-12 10:44 206,256 ----a-w c:\windows\system32\idmmbc.dll
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\dllcache\msxml6.dll
2008-09-08 10:41 333,824 ----a-w c:\windows\system32\dllcache\srv.sys
2008-09-06 07:30 241,704 ------w c:\windows\system32\dllcache\wgaLogon.dll
2008-09-06 07:29 917,032 ------w c:\windows\system32\dllcache\WgaTray.exe
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\dllcache\msxml3.dll
2008-08-27 21:54 3,593,216 ------w c:\windows\system32\dllcache\mshtml.dll
2008-08-25 08:38 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-08-25 08:38 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [01/19/2007 12:55 PM 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/14/2008 12:00 PM 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [11/23/2008 11:46 AM 2606512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [07/29/2008 08:20 PM 206088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [06/19/2007 10:17 AM 1241088]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/14/2008 12:00 PM 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 04/14/2008 12:00 PM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 11/23/2008 11:46 AM 2606512 c:\program files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 04/14/2008 04:00 AM 208952 c:\windows\ime\imjp8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 01/19/2007 12:55 PM 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
--a------ 04/14/2008 04:00 AM 59392 c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
--a------ 03/31/2008 05:54 PM 507904 c:\program files\Winamp Remote\bin\OrbTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 06/18/2007 03:10 PM 271360 c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 04/14/2008 04:00 AM 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 04/14/2008 04:00 AM 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 11/24/2008 03:40 PM 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 10/09/2007 09:28 PM 36352 c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-ra------ 11/30/2004 11:54 PM 77824 c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Yasser Hamde\Application Data\Mozilla\Firefox\Profiles\sjf7p71m.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-25 01:33:47
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(800)
c:\windows\system32\WgaLogon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\wdfmgr.exe
c:\program files\Mozilla Firefox\firefox.exe
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 11/25/2008 1:39:25 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-25 09:39:02
Pre-Run: 5,631,180,800 bytes free
Post-Run: 5,636,530,176 bytes free
186 --- E O F --- 2008-11-25 01:56:46