ComboFix 08-08-21.02 - l 08/23/2008 3:10:10.2 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.471 [GMT 3:00]
Running from: C:\Documents and Settings\l\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-07-23 to 2008-08-23 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-23 00:05 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-23 00:05 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-23 00:05 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-23 00:05 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-21 23:46 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-21 23:29 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-08-21 23:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-13 18:05 --------- d-----w C:\Documents and Settings\l\Application Data\ADPHONE
2008-08-11 00:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-08-10 16:38 53,248 ----a-w C:\WINDOWS\system32\zlib.dll
2008-08-10 16:38 53,248 ----a-w C:\WINDOWS\system32\sysdat.dll
2008-08-10 16:38 --------- d-----w C:\Program Files\CequenzeTech
2008-08-07 02:00 --------- d-----w C:\Program Files\RSCTool
2008-08-07 00:25 --------- d-----w C:\Documents and Settings\l\Application Data\URSoft
2008-08-07 00:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-04 19:54 286,720 ------w C:\WINDOWS\Setup1.exe
2008-07-29 17:21 218,376 ----a-w C:\WINDOWS\system32\klogon.dll
2008-07-29 17:20 24,774 ----a-w C:\WINDOWS\system32\drivers\klopp.dat
2008-07-21 15:34 121,872 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-07-07 20:27 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:27 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-28 00:08 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-28 00:08 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-06-28 00:06 --------- d-----w C:\Documents and Settings\l\Application Data\PC Suite
2008-06-28 00:06 --------- d-----w C:\Documents and Settings\l\Application Data\Nokia
2008-06-28 00:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-06-28 00:05 --------- d-----w C:\Program Files\DIFX
2008-06-28 00:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-06-26 14:22 --------- d-----w C:\Program Files\TryMedia
2008-06-25 15:38 47,104 ------w C:\WINDOWS\AKDeInstall.exe
2008-06-25 15:38 --------- d-----w C:\Program Files\mpegable
2008-06-25 15:37 --------- d-----w C:\Documents and Settings\l\Application Data\Skype
2008-06-25 15:36 --------- d-----w C:\Program Files\Skype
2008-06-25 15:36 --------- d-----w C:\Program Files\Common Files\Skype
2008-06-25 13:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Eset
2008-06-25 02:10 --------- d-----w C:\Program Files\MSXML 4.0
2008-06-24 22:24 --------- d-----w C:\Program Files\Common Files\Download Manager
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:43 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 07:15 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-24 01:43 --------- d-----w C:\Program Files\Virtual sMs Handset
2008-06-23 14:47 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-23 09:18 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:18 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-21 05:23 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:47 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:47 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:47 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-14 17:31 271,616 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-05-10 15:10 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008051020080511\index.dat
.
كود:
<pre>
----a-w 25,034,985 2002-11-17 16:44:54 C:\Documents and Settings\l\سطح المكتب\جلمود ®2008\متفرقات\الوافي ®الذهبي .exe
</pre>
((((((((((((((((((((((((((((( snapshot@Sat 08-23-2008_ 3.08.27.50 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-22 23:54:54 63,370 ----a-w C:\WINDOWS\system32\perfc001.dat
+ 2008-08-23 00:11:42 63,370 ----a-w C:\WINDOWS\system32\perfc001.dat
- 2008-08-22 23:54:54 63,266 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-08-23 00:11:42 63,266 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-22 23:54:54 339,202 ----a-w C:\WINDOWS\system32\perfh001.dat
+ 2008-08-23 00:11:42 339,202 ----a-w C:\WINDOWS\system32\perfh001.dat
- 2008-08-22 23:54:54 403,664 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-08-23 00:11:42 403,664 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [05/10/2008 11:00 PM 68856]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 11:34 AM 5724184]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [04/14/2008 06:59 PM 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 10:50 AM 155648]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 01:06 PM 40048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05/06/2008 09:53 PM 185896]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [07/29/2008 08:20 PM 206088]
"Device Detector"="DevDetect.exe" [N/A]
"SystemInit"="" [N/A]
"Karen"="" [N/A]
"raVe"="" [N/A]
"Win32BaseServiceMOD"="" [N/A]
"startIE"="" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"raVe"="" [N/A]
"Driver32"="" [N/A]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
C:\Documents and Settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Orbit.lnk - C:\Program Files\Orbitdownloader\orbitdm.exe [2008-05-06 21:57:45 1678536]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoRun"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 10/18/2007 11:34 AM 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 04/23/2008 05:45 PM 22058792 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/30/2008 06:06 PM]
S3 SetupNTGLM7X;SetupNTGLM7X;F:\NTGLM7X.sys []
.
- - - - ORPHANS REMOVED - - - -
BHO-{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\l\Application Data\Mozilla\Firefox\Profiles\flm7ctol.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://free-world.ahlamountada.com/
.
.
------- File Associations (Beta) -------
.
txtfile=NOTEPAD %1
vbefile\shell\edit\command=C:\WINDOWS\Notepad.exe %1
vbsfile\shell\edit\command=C:\WINDOWS\Notepad.exe %1
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-23 03:14:04
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 08/23/2008 3:15:51
ComboFix-quarantined-files.txt 2008-08-23 00:15:50
Pre-Run: 35,909,074,944 bytes free
Post-Run: 35,895,705,600 bytes free
185 --- E O F --- 2008-08-14 23:21:02