ComboFix 08-11-30.01 - Amr 11/30/2008 22:08:47.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.172 [GMT 2:00]
Running from: c:\documents and settings\Amr\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\e.cmd
C:\i.bat
c:\windows\system32\divx.dll
c:\windows\system32\gasretyw0.dll
c:\windows\system32\gasretyw1.dll
c:\windows\system32\kamsoft.exe
D:\Autorun.inf
D:\e.cmd
D:\i.bat
D:\ij.bat
D:\m2nl.bat
E:\Autorun.inf
E:\e.cmd
E:\i.bat
E:\ij.bat
E:\m2nl.bat
F:\Autorun.inf
F:\e.cmd
F:\i.bat
F:\ij.bat
F:\m2nl.bat
.
((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-30 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-30 20:11 90,144 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-30 20:11 3,236 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-30 20:11 276,000 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-30 20:11 1,388 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-30 20:11 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-30 18:36 96,645 ----a-w c:\windows\system32\drivers\klin.dat
2008-11-30 18:36 87,941 ----a-w c:\windows\system32\drivers\klick.dat
2008-11-29 09:17 111,636 --sh--r C:\o1.com
2008-11-28 19:41 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-11-28 19:40 --------- d-----w c:\program files\Yahoo!
2008-11-28 18:59 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-28 18:59 --------- d-----w c:\documents and settings\Amr\Application Data\bsplayer
2008-11-28 18:59 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-28 18:51 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-28 18:51 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-28 18:39 --------- d-----w c:\program files\Kaspersky Lab
2008-11-28 18:29 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-28 18:21 --------- d-----w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [09/01/2004 06:00 AM 15360]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [11/06/2007 07:51 PM 3810544]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [08/04/2004 01:06 AM 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [02/23/2005 12:13 PM 77824 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [09/01/2004 06:00 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll
"VIDC.VP31"= vp31vfw.dll
"msacm.l3fhg"= mp3fhg.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592]
S3 AVPsys;AVPsys;\??\c:\windows\system32\drivers\cdaudio.sys [2001-08-17 18688]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3cd16ac5-bd7a-11dd-a8a5-001485cde3d8}]
\Shell\AutoRun\command - H:\o1.com
\Shell\explore\Command - H:\o1.com
\Shell\open\Command - H:\o1.com
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Amr\Application Data\Mozilla\Firefox\Profiles\j1fy7c36.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-30 22:12:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(808)
c:\windows\system32\klogon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 11/30/2008 22:13:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-30 20:13:48
Pre-Run: 7,631,265,792 bytes free
Post-Run: 7,611,244,544 bytes free
123