ComboFix 08-08-12.01 - Free User 08/13/2008 23:08:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.38 [GMT 3:00]
Running from: C:\Documents and Settings\Free User\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\Documents and Settings\Free User\Application Data\macromedia\Flash Player\#Shareds\AL2GJRSR\iforex.com
C:\Documents and Settings\Free User\Application Data\macromedia\Flash Player\#Shareds\AL2GJRSR\iforex.com\Emerp\Events\flash_.swf\user_data.sol
C:\Documents and Settings\Free User\Application Data\macromedia\Flash Player\#Shareds\AL2GJRSR\interclick.com
C:\Documents and Settings\Free User\Application Data\macromedia\Flash Player\#Shareds\AL2GJRSR\interclick.com\ud.sol
C:\Documents and Settings\Free User\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\Free User\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\Documents and Settings\Free User\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Free User\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\Data(1).dll
C:\WINDOWS\system32\Data(2).dll
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\win.dll
C:\WINDOWS\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-13 to 2008-08-13 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-13 20:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-13 20:14 483,360 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-13 20:14 22,400 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-13 20:14 2,732 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-13 20:14 2,594,848 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-11 17:12 --------- d-----w C:\Program Files\ESET
2008-08-11 00:11 --------- d-----w C:\Program Files\Microsoft Works
2008-08-10 22:01 --------- d-----w C:\Documents and Settings\Free User\Application Data\cleaner
2008-08-10 21:36 --------- d-sha-r C:\Program Files\Golden Filter Pro
2008-08-10 00:24 --------- d-----w C:\Documents and Settings\Free User\Application Data\Theadmin
2008-08-06 22:27 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-04 07:17 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-08-02 02:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Long slow road itch
2008-07-29 12:00 --------- d-----w C:\Program Files\Internet Download Manager
2008-07-29 11:27 --------- d-----w C:\Documents and Settings\Free User\Application Data\DMCache
2008-07-24 13:31 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-23 19:08 --------- d-----w C:\Program Files\SpeedyGuide 2
2008-07-23 15:02 --------- d-----w C:\Program Files\Theadmin
2008-07-17 08:35 --------- d-----w C:\Program Files\Hidetools Child Control
2008-07-16 06:10 --------- d-----w C:\Program Files\MSN Messenger
2008-07-13 10:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\zyz Kaspersky Lab setup files
2008-07-12 00:02 --------- d-----w C:\Program Files\MSXML 4.0
2008-07-11 09:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-11 09:18 17,801 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-07-11 09:17 --------- d-----w C:\Program Files\Atheros
2008-07-11 09:15 --------- d-----w C:\Documents and Settings\Free User\Application Data\Intel
2008-07-11 09:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intel
2008-07-11 09:12 --------- d-----w C:\Program Files\Intel
2008-07-11 09:07 --------- d-----w C:\Program Files\Realtek
2008-07-11 08:01 --------- d-----w C:\Documents and Settings\Free User\Application Data\IDM
2008-07-03 18:55 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-26 10:27 2,846,720 ----a-w C:\WINDOWS\system32\agsaamj.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 11:05 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-22 14:30 90,112 ----a-w C:\WINDOWS\system32\ssvideo.dll
2008-05-22 14:30 19,456 ----a-w C:\WINDOWS\system32\videocore.dll
2008-05-22 14:30 18,595,840 ----a-w C:\WINDOWS\system32\coredata.dll
2008-05-22 14:30 1,128,128 ----a-w C:\WINDOWS\system32\NMSDVDXU.dll
2008-05-18 22:15 3,203,828 ----a-w C:\WINDOWS\REGBK00.ZIP
2008-05-18 22:14 17,291,824 ----a-w C:\WINDOWS\hkcrRT.reg
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\doraemonmsgr.exe" [01/19/2007 12:55 PM 6475632]
"Hidetools Child Control"="C:\Program Files\Hidetools Child Control\ccon.exe" [05/27/2008 09:55 PM 811520]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 03:12 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [06/08/2005 06:02 AM 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [06/08/2005 05:59 AM 77824]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [06/11/2005 02:51 PM 53248]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [10/08/2004 09:44 AM 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [10/08/2004 09:43 AM 688218]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [11/02/2004 09:24 PM 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 11:50 AM 155648]
"WIML"="C:\WINDOWS\system32\msnqp.exe" [10/09/2007 02:28 AM 73728]
"RMCPL"="C:\WINDOWS\system32\wnpnl.exe" [10/09/2007 01:59 AM 81920]
"MSNR"="C:\WINDOWS\system32\msnqp.exe" [10/09/2007 02:28 AM 73728]
"MSNQ"="C:\WINDOWS\system32\wnpnl.exe" [10/09/2007 01:59 AM 81920]
"VerbAce"="C:\Program Files\VerbAce\VerbAce.exe" [02/08/2008 07:38 PM 139264]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 01:06 PM 40048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [04/13/2008 07:12 PM 185896]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" [11/03/2007 04:50 AM 6731312]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [10/15/2004 11:27 AM 385024]
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" [10/15/2004 11:31 AM 356352]
"ACU"="C:\Program Files\Atheros\ACU.exe" [01/31/2005 08:05 AM 253952]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"BluetoothAuthenticationAgent"="bthprops.cpl" [04/14/2008 03:12 AM 110592 C:\WINDOWS\system32\bthprops.cpl]
"RTHDCPL"="RTHDCPL.EXE" [08/09/2005 10:17 AM 14743552 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 03:12 AM 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-02-13 07:49:47 113664]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoRun"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
10/15/2004 11:27 AM 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\doraemonmsgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM]
.
s of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-GoldenFilterPro - C:\Program Files\Golden Filter Pro\GFPro.exe
HKLM-Run-SystemInit - (no file)
HKLM-Run-Karen - (no file)
HKLM-Run-raVe - (no file)
HKLM-Run-Win32BaseServiceMOD - (no file)
HKLM-Run-startIE - (no file)
HKLM-RunServices-raVe - (no file)
HKLM-RunServices-Driver32 - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
R0 -: HKCU-Main,Start Page = about:blank
R1 -: HKCU-Internet Settings,ProxyServer = 212.93.193.80:8080
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
O16 -: {3C8E8DD8-D86A-4E6D-AF37-AB3CA7FDF8CD} - hxxp://74.53.137.146/imscp/talkc38.cab
C:\WINDOWS\Downloaded Program Files\talkc38.inf
C:\WINDOWS\Downloaded Program Files\IMSConf38.dll
O16 -: {6924091F-CD97-41E1-B1D4-D9079409D413} - hxxp://74.53.137.146/imscp/talka.cab
C:\WINDOWS\Downloaded Program Files\talk.inf
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mfc42.dll
C:\WINDOWS\system32\olepro32.dll
C:\WINDOWS\Downloaded Program Files\imcv1.dll
C:\WINDOWS\Downloaded Program Files\IMSInfo.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-13 23:24:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Free User\Desktop\Opera\op.com
C:\Program Files\MSN Messenger\usnsvc.exe
.
**************************************************************************
.
Completion time: 08/13/2008 23:36:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-13 20:36:40
Pre-Run: 1,184,419,840 bytes free
Post-Run: 1,072,771,072 bytes free
211 --- E O F --- 2008-08-13 17:17:12