ComboFix 08-12-03.04 - BSD 12/04/2008 17:49:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.907 [GMT 2:00]
Running from: c:\documents and settings\BSD\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\BSD\Desktop\control lab mi\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف\CPU_lab\cpu _ALU\unit 2\CPUCodeGenerator\AluCodeGenerator\bin\Debug\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit 2\CPUCodeGenerator\AluCodeGenerator\bin\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit 2\CPUCodeGenerator\AluCodeGenerator\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit 2\CPUCodeGenerator\AluCodeGenerator\obj\Debug\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit 2\CPUCodeGenerator\AluCodeGenerator\obj\Debug\TempPE\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit 2\CPUCodeGenerator\AluCodeGenerator\obj\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit 2\CPUCodeGenerator\AluCodeGenerator\Properties\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit 2\CPUCodeGenerator\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit 2\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit1\CPU_CONTROL_UNIT_1\bin\Debug\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit1\CPU_CONTROL_UNIT_1\bin\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit1\CPU_CONTROL_UNIT_1\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit1\CPU_CONTROL_UNIT_1\obj\Debug\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit1\CPU_CONTROL_UNIT_1\obj\Debug\TempPE\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit1\CPU_CONTROL_UNIT_1\obj\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit1\CPU_CONTROL_UNIT_1\Properties\Desktop_.ini
c:\documents and settings\BSD\Desktop\ملف \CPU_lab\cpu _ALU\unit1\Desktop_.ini
c:\program files\ShoppingReport
c:\program files\ShoppingReport\Uninst.exe
c:\windows\system32\mdm.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2008-11-04 to 2008-12-04 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-04 16:02 3,929,888 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-12-04 16:02 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-04 16:01 64,178,720 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-04 16:00 865,688 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-04 16:00 374,600 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-12-04 15:48 --------- d-----w c:\documents and settings\BSD\Application Data\DMCache
2008-12-04 07:25 --------- d-----w c:\documents and settings\All Users\Application Data\Urban FreeStyle Soccer
2008-12-04 07:23 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-04 07:23 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-02 18:35 --------- d-----w c:\documents and settings\BSD\Application Data\U3
2008-11-27 16:31 --------- d-----w c:\documents and settings\BSD\Application Data\MathWorks
2008-11-25 21:51 --------- d-----w c:\program files\Craft s
2008-11-22 18:17 --------- d-----w c:\documents and settings\BSD\Application Data\Nuotex
2008-11-20 16:20 --------- d-----w c:\documents and settings\BSD\Application Data\Eidos
2008-11-20 14:50 --------- d-----w c:\documents and settings\BSD\Application Data\Disney Interactive Studios
2008-11-16 18:54 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-11-15 04:44 --------- d-----w c:\program files\Cossacks 2 - Demo
2008-11-13 23:08 --------- d-----w c:\program files\Holomatix
2008-11-13 23:06 --------- d-----w c:\documents and settings\BSD\Application Data\{A227CC19-656C-41E2-A664-E5BF39A1547D}
2008-11-13 10:47 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-12 14:44 --------- d-----w c:\program files\Windows Media Connect 2
2008-11-11 12:42 --------- d-----w c:\program files\Activision
2008-11-05 16:43 --------- d-----w c:\program files\Sierra Wireless Inc
2008-11-05 16:42 --------- d-----w c:\documents and settings\BSD\Application Data\Sierra Wireless
2008-10-30 12:44 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-10-29 18:52 256 ----a-w C:\control_unit1.bin
2008-10-29 18:51 256 ----a-w C:\control1.bin
2008-10-28 19:43 --------- d-----w c:\program files\Common Files\GuruNet Shared
2008-10-28 19:43 --------- d-----w c:\program files\Common Files\Accent Shared
2008-10-28 16:39 --------- d-----w c:\program files\PopCap Games
2008-10-26 13:59 --------- d-----w c:\documents and settings\BSD\Application Data\ooVoo Details
2008-10-24 15:24 --------- d-----w c:\documents and settings\All Users\Application Data\nView_Profiles
2008-10-24 15:06 10,200 ------w c:\windows\_000005_.tmp.dll
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-18 07:16 --------- d-----w c:\program files\Windows Live
2008-10-15 20:30 --------- d-----w c:\documents and settings\BSD\Application Data\Windows Live Writer
2008-10-14 13:16 --------- d-----w c:\program files\Xilisoft
2008-10-11 23:02 --------- d-----w c:\program files\Microsoft Office Outlook Connector
2008-10-11 22:58 --------- d-----w c:\program files\Microsoft
2008-10-11 22:48 --------- d-----w c:\program files\Common Files\Windows Live
2008-10-11 13:25 --------- d-----w c:\program files\Common Files\ChaosGroup
2008-10-10 08:43 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-10-06 17:11 --------- d-----w c:\program files\WIBUKEY
2008-10-06 17:11 --------- d-----w c:\program files\WIBU-SYSTEMS
2008-10-05 16:53 --------- d-----w c:\program files\Common Files\Adobe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
07/28/2008 12:46 PM 160496 --a------ c:\program files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/14/2008 02:12 AM 15360]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [11/05/2008 09:59 PM 4424944]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [09/09/2008 12:02 AM 3513344]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [08/03/2007 12:51 PM 271656]
"Google Update"="c:\documents and settings\BSD\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [09/02/2008 10:14 PM 206832]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [10/07/2008 05:23 PM 189680]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [10/04/2007 11:14 AM 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [10/04/2007 11:14 AM 81920]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [03/01/2007 03:57 PM 222768]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [08/08/2007 09:25 AM 1897768]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [08/22/2008 01:08 AM 259624]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 03:27 AM 214416]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [01/20/2007 09:09 AM 278528]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [08/24/2007 06:00 AM 103280]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [10/07/2008 05:23 PM 189680]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [06/28/2007 12:51 PM 218376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [04/14/2008 02:12 AM 15360]
c:\documents and settings\BSD\Start Menu\Programs\Startup\
is-DE8DA.lnk - c:\documents and settings\BSD\Desktop\Virus Removal Tool\is-DE8DA\startup.exe [2008-12-03 65536]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-03-05 11000]
DRSpawner.lnk - c:\documents and settings\All Users\Application Data\ASGvis\DRSpawner\DRSpawner.exe [2008-09-11 1814528]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 7.0\\avp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\BSD\\My Documents\\Downloads\\Compressed\\Rendition_1.0.372\\Rendition_1.0.372\\Rendition.exe"=
"e:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"e:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe"=
"c:\\WINDOWS\\system32\\vsjitdebugger.exe"=
"c:\\Program Files\\Common Files\\Nero\\Lib\\NeroCheck.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\ASGvis\\DRSpawner\\DRSpawner.exe"=
"d:\\matlab7\\bin\\win32\\matlab.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\Program Files\\Common Files\\Nero\\Lib\\NMIndexStoreSvr.exe"=
"c:\\Program Files\\Nero\\Nero8\\Nero BackItUp\\NBKeyScan.exe"=
"c:\\Documents and Settings\\BSD\\Desktop\\Virus Removal Tool\\is-DE8DA\\is-DE8DA.exe"=
"c:\\Program Files\\PowerISO\\PWRISOVM.EXE"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe"=
"c:\\DOCUME~1\\BSD\\LOCALS~1\\Temp\\winamttag.exe"=
"c:\\DOCUME~1\\BSD\\LOCALS~1\\Temp\\winxsxdw.exe"=
"c:\\DOCUME~1\\BSD\\LOCALS~1\\Temp\\winijkgnx.exe"=
R1 is-DE8DAdrv;is-DE8DAdrv;c:\windows\system32\DRIVERS\72037796.sys [2008-12-03 148496]
R2 WKSVW32;WIBU-KEY Server;c:\program files\WIBUKEY\SERVER\WkSvW32.exe [2008-10-06 577536]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-04-04 24344]
R3 swivsp;AC8xx Virtual Serial Port;c:\windows\system32\DRIVERS\swivspnt.sys [2007-03-26 20352]
S3 SWNC8U80;Sierra Wireless MUX NDIS Driver (UMTS80);c:\windows\system32\DRIVERS\swnc8u80.sys [2008-05-20 167040]
S3 SWUMX80;Sierra Wireless USB MUX Driver (UMTS80);c:\windows\system32\DRIVERS\swumx80.sys [2008-05-20 143360]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 [2005-09-23 2799808]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0460296-bc6e-11dd-a83f-001b22059b38}]
\Shell\AutoRun\command - fnexsjs.exe
\Shell\explore\Command - fnexsjs.exe
\Shell\open\Command - fnexsjs.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6b01163-9c28-11dd-aec8-001b22059b38}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6b01164-9c28-11dd-aec8-001b22059b38}]
\Shell\AutoRun\command - kinza.exe
\Shell\explore\Command - kinza.exe
\Shell\open\Command - kinza.exe
*Newly Created Service* - ASC3360PR
.
s of the 'Scheduled Tasks' folder
2008-12-03 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\BSD\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [09/02/2008 10:14 PM]
2008-12-03 c:\windows\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe []
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
HKCU-Run-Steam - d:\cs\Counter-Strike Source\Steam.exe
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\docume~1\BSD\LOCALS~1\Temp\Rar$EX22.297\Internet_Download_Manager_5.12_Build_7\Internet Download Manager 5.12 Build 7\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\docume~1\BSD\LOCALS~1\Temp\Rar$EX22.297\Internet_Download_Manager_5.12_Build_7\Internet Download Manager 5.12 Build 7\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\docume~1\BSD\LOCALS~1\Temp\Rar$EX22.297\Internet_Download_Manager_5.12_Build_7\Internet Download Manager 5.12 Build 7\IEGetVL.htm
LSP: c:\windows\system32\idmmbc.dll
TCP: {FDE3A087-0FCE-4AE9-8E27-2A1461C96E1B} = 212.14.224.1,212.150.48.169
c:\windows\Downloaded Program Files\installer.ocx - O16 -: {82FFA573-38AA-482A-99AD-91F697B91631}
hxxp://f300ce3177d433319cded8ba6b0e860c.impregnable.net/get.php/dl_applet.cab?t=1219298422&h=aefda1062ccfca0e10a1d684714d0067&f=tfmb.cab&fn=/dl_applet.cab
c:\windows\Downloaded Program Files\installer.INF
FireFox -: Profile - c:\documents and settings\BSD\Application Data\Mozilla\Firefox\Profiles\9on75n8d.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-ytbm&p=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/
FF -: plugin - c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF -: plugin - c:\documents and settings\BSD\Local Settings\Application Data\Google\Update\1.2.131.19\npGoogleOneClick6.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
FF -: plugin - d:\basheeer\DivX Player\npDivxPlayerPlugin.dll
FF -: plugin - d:\basheeer\DivX Web Player\npdivx32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-04 18:01:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1112)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1168)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\windows\system32\idmmbc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
d:\matlab7\bin\win32\MATLAB.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\windows\system32\wscntfy.exe
c:\docume~1\BSD\LOCALS~1\Temp\winamttag.exe
c:\docume~1\BSD\LOCALS~1\Temp\winxsxdw.exe
c:\docume~1\BSD\LOCALS~1\Temp\winijkgnx.exe
.
**************************************************************************
.
Completion time: 12/04/2008 18:10:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-04 16:10:38
Pre-Run: 3,738,628,096 bytes free
Post-Run: 6,727,823,360 bytes free
253 --- E O F --- 2008-11-22 05:06:37