[ComboFix 08-12-01.03 - HAR 12/04/2008 15:39:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.621 [GMT 3:00]
Running from: c:\documents and settings\HAR\My Documents\Downloads\Programs\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HAR\Application Data\GetModule
c:\documents and settings\HAR\Application Data\GetModule\kwdik.gz
c:\documents and settings\HAR\Application Data\GetModule\ofadik.gz
c:\windows\IE4 Error Log.txt
c:\windows\system32\ckqyidcm.ini
c:\windows\system32\goggmbvv.ini
c:\windows\system32\ichmehst.ini
c:\windows\system32\mcdiyqkc.dll
c:\windows\system32\slsumrwm.ini
c:\windows\system32\update
c:\windows\system32\Winainit.dll
c:\windows\system32\yxybayxx.ini
c:\windows\system32\yxybayxx.ini2
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-11-04 to 2008-12-04 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-04 12:43 17,678,112 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-04 12:43 1,066,272 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-12-04 12:42 252,404 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-04 12:42 110,408 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-12-04 12:39 --------- d-----w c:\documents and settings\HAR\Application Data\DMCache
2008-12-04 12:35 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-04 12:24 --------- d-----w c:\documents and settings\HAR\Application Data\IDM
2008-12-04 12:05 --------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2008-12-04 11:52 --------- d-----w c:\documents and settings\Administrator\Application Data\IDM
2008-12-04 03:35 --------- d-----w c:\program files\SUPERAntiSpyware
2008-12-04 03:35 --------- d-----w c:\documents and settings\HAR\Application Data\SUPERAntiSpyware.com
2008-12-04 03:35 --------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-04 03:33 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-04 01:33 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-03 23:42 --------- d-----w c:\documents and settings\HAR\Application Data\uTorrent
2008-12-03 10:25 --------- d-----w c:\program files\Magic Flare
2008-12-03 10:25 --------- d-----w c:\program files\LimeWire
2008-12-03 10:23 --------- d-----w c:\program files\Hotspot_Shield
2008-12-03 10:23 --------- d-----w c:\program files\Conduit
2008-12-03 10:21 --------- d-----w c:\documents and settings\HAR\Application Data\4shared Uploader
2008-12-03 01:58 --------- d-----w c:\program files\shup
2008-12-02 16:29 --------- d-----w c:\program files\iTunes
2008-12-02 16:29 --------- d-----w c:\program files\iPod
2008-12-02 16:29 --------- d-----w c:\documents and settings\HAR\Application Data\Apple Computer
2008-12-02 16:29 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-02 16:29 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-02 16:28 --------- d-----w c:\program files\QuickTime
2008-12-02 16:28 --------- d-----w c:\program files\Bonjour
2008-12-02 16:27 --------- d-----w c:\program files\Apple Software Update
2008-12-02 16:26 --------- d-----w c:\program files\Common Files\Apple
2008-12-02 16:26 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-11-29 20:28 --------- d-----w c:\program files\Hotspot Shield
2008-11-29 14:45 --------- d-----w c:\documents and settings\HAR\Application Data\U3
2008-11-28 08:01 --------- d-----w c:\program files\Golden Al-Wafi Translator
2008-11-27 00:48 --------- d-----w c:\documents and settings\HAR\Application Data\LimeWire
2008-11-26 10:31 --------- d-----w c:\documents and settings\HAR\Application Data\Leadertech
2008-11-26 10:30 --------- d-----w c:\documents and settings\HAR\Application Data\AdobeAUM
2008-11-25 10:37 --------- d-----w c:\program files\XviD
2008-11-25 10:37 --------- d-----w c:\program files\x264
2008-11-23 10:24 --------- d-----w c:\program files\Internet Download Manager
2008-11-22 20:20 --------- d-----w c:\program files\TrackerChecker
2008-11-22 16:07 30 ----a-w c:\documents and settings\HAR\jagex_runescape_preferences.dat
2008-11-21 07:35 --------- d-----w c:\documents and settings\All Users\Application Data\IJJIGame
2008-11-20 22:22 --------- d-----w c:\program files\Passware
2008-11-19 15:13 --------- d-----w c:\program files\BitLord
2008-11-15 16:24 --------- d-----w c:\program files\SystemRequirementsLab
2008-11-15 16:21 --------- d-----w c:\documents and settings\HAR\Application Data\SystemRequirementsLab
2008-11-14 12:41 --------- d-----w c:\program files\Messenger Plus! Live
2008-11-14 12:41 --------- d-----w c:\program files\Circle Developement
2008-11-14 11:41 --------- d-----w c:\program files\MessengerLog
2008-11-14 11:41 --------- d-----w c:\documents and settings\HAR\Application Data\MessengerLog6
2008-11-14 11:24 --------- d-----w c:\program files\Network Stumbler
2008-11-13 13:09 --------- d-----w c:\program files\FileZilla
2008-11-11 19:26 --------- d-----w c:\program files\CONEXANT
2008-11-11 19:08 --------- d-----w c:\program files\MSXML 4.0
2008-11-11 12:50 --------- d-----w c:\program files\ProxyFirewall
2008-11-10 21:21 --------- d-----w c:\program files\Ares
2008-11-10 20:49 79,088 ----a-w c:\windows\system32\dnzxxjsbnva.exe
2008-11-09 18:26 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-09 18:23 --------- d-----w c:\program files\Microsoft ActiveSync
2008-11-06 21:01 580,114 ----a-w c:\windows\system32\x264vfw.dll
2008-11-05 17:29 --------- d-----w c:\documents and settings\HAR\Application Data\dvdcss
2008-11-04 10:46 --------- d-----w c:\program files\MassMirror
2008-11-02 10:15 --------- d-----w c:\documents and settings\HAR\Application Data\SmartFTP
2008-11-01 16:40 --------- d-----w c:\program files\Gabest
2008-11-01 06:13 --------- d-----w c:\documents and settings\All Users\Application Data\Torrent2Exe
2008-10-27 23:42 --------- d-----w c:\documents and settings\All Users\Application Data\Downloaded Installations
2008-10-27 10:49 --------- d-----w c:\documents and settings\HAR\Application Data\Diino
2008-10-25 19:18 --------- d-----w c:\program files\Allok RM RMVB to AVI MPEG DVD Converter
2008-10-25 14:40 --------- d-----w c:\documents and settings\HAR\Application Data\Ahead
2008-10-25 14:37 --------- d-----w c:\program files\Common Files\Ahead
2008-10-25 14:37 --------- d-----w c:\documents and settings\All Users\Application Data\Ahead
2008-10-25 14:34 --------- d-----w c:\program files\Nero
2008-10-25 14:34 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 09:50 --------- d-----w c:\documents and settings\HAR\Application Data\Datalayer
2008-10-24 05:56 --------- d-----w c:\documents and settings\HAR\Application Data\Nokia
2008-10-24 05:53 --------- d-----w c:\program files\DIFX
2008-10-24 05:53 --------- d-----w c:\documents and settings\HAR\Application Data\PC Suite
2008-10-24 05:53 --------- d-----w c:\documents and settings\All Users\Application Data\PC Suite
2008-10-23 19:03 --------- d-----w c:\program files\URUSoft
2008-10-23 05:19 73,216 ----a-w c:\windows\ST6UNST.EXE
2008-10-23 05:19 172,032 ------w c:\windows\Setup1.exe
2008-10-23 04:54 --------- d-----w c:\program files\BT Engine
2008-10-23 00:44 361,344 ----a-w c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2008-10-22 23:14 --------- d-----w c:\documents and settings\HAR\Application Data\Media Player Classic
2008-10-22 23:05 --------- d-----w c:\program files\K-Lite Codec Pack
2008-10-22 18:49 --------- d-----w c:\program files\uTorrent
2008-10-22 14:29 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-10-17 13:50 225,280 --sha-r c:\windows\system32\userjnit.exe
2008-10-16 11:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 11:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 11:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 11:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 11:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 11:09 51,224 ------w c:\windows\system32\wuauclt.exe
2008-10-16 11:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 11:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-13 11:23 --------- d-----w c:\documents and settings\HAR\Application Data\CyberLink
2008-10-08 20:30 --------- d-----w c:\documents and settings\HAR\Application Data\AdobeUM
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
11/29/2008 11:29 PM 204248 --a------ c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"aamd535.dll"="c:\docume~1\HAR\LOCALS~" [X]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [11/13/2006 01:39 PM 1289000]
"WinTrySys"="c:\windows\system32\userjnit.exe" [10/17/2008 04:50 PM 225280]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/15/2008 03:00 PM 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [11/17/2008 03:11 PM 1805552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [07/12/2002 06:15 PM 106496]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [12/05/2006 10:55 PM 54832]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [11/26/2007 02:54 PM 1629480]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [11/04/2008 10:30 AM 413696]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [11/23/2006 03:10 PM 56928]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [03/01/2007 02:57 PM 153136]
"SoundMan"="SOUNDMAN.EXE" [08/03/2006 05:12 AM 577536 c:\windows\soundman.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [04/15/2008 03:00 PM 110592 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/15/2008 03:00 PM 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2008-10-03 331776]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [05/13/2008 09:13 AM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
07/23/2008 03:28 PM 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"vidc.X264"= x264vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 04/15/2008 03:00 PM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Explorer]
--a------ 04/15/2008 03:00 PM 1031168 c:\windows\explorer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 11/26/2007 02:54 PM 1057064 c:\program files\Nero\Nero 7\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 11/20/2008 01:20 PM 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-11-17 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-11-17 55024]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-04-04 24344]
R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-11-17 7408]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;\??\c:\windows\system32\NSNDIS5.SYS []
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [2008-10-22 194304]
S3 WZCOOK;WEP/WPA-PMK key recovery service;"c:\documents and settings\HAR\My Documents\Downloads\Cracking_WiFi_Connections\crackeo de redes wi fi + programas\WinAircrackPack\WinAircrackPack\WinAircrackPack\wzcook.exe" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7ec83bce-be3d-11dd-aaba-00c0ca1e83fe}]
\Shell\AutoRun\command - G:\skin.EXE /AUTORUN
\Shell\explore\Command - G:\skin.exe
\Shell\open\Command - G:\skin.exe
.
s of the 'Scheduled Tasks' folder
2008-12-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [07/30/2008 12:34 PM]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DLD.EXE - c:\program files\Download Direct\DLD.exe
HKCU-Run-GetModule30 - c:\program files\GetModule\GetModule30.exe
HKCU-Run-TrackerChecker - (no file)
HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
Notify-ljJCRiFv - (no file)
MSConfigStartUp-Torrent2Exe[01a7108f1ca1423618f1110046794646fbca12a4] - c:\documents and settings\HAR\سطح المكتب\88.exe
MSConfigStartUp-Torrent2Exe[0cce900bb649a78cfe43237eeebd008eb8d71934] - c:\documents and settings\HAR\سطح المكتب\d.exe
MSConfigStartUp-Torrent2Exe[8af33e7f28c99d0e2a57fd8f3952d0abab72f78b] - c:\documents and settings\HAR\سطح المكتب\999.exe
MSConfigStartUp-Torrent2Exe[95adbf7c238a59e2a04bf2a1fb2bc7f6b68d8935] - c:\documents and settings\HAR\سطح المكتب\444.exe
MSConfigStartUp-Torrent2Exe[b96b862a1805c889e969697c8e7436c576786d2e] - c:\documents and settings\HAR\سطح المكتب\tt.exe
MSConfigStartUp-Torrent2Exe[c77c317378d8a4fe4539331a262357698bbaf465] - c:\documents and settings\HAR\سطح المكتب\23.exe
MSConfigStartUp-Torrent2Exe[ee0fafa8abfddf746860985733d06670d3a83637] - c:\documents and settings\HAR\سطح المكتب\kk.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\HAR\Application Data\Mozilla\Firefox\Profiles\x3zfl1an.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q=
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-04 15:43:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1316)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1372)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\rundll32.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\qoobox\Quarantine\C\WINDOWS\system32\Winainit.dll.vir1a9}
.
**************************************************************************
.
Completion time: 12/04/2008 15:46:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-04 12:46:40
Pre-Run: 28,581,212,160 bytes free
Post-Run: 28,698,775,552 bytes free
267 --- E O F --- 2008-12-03 22:53:48
هذا تقرير من برنامج