ComboFix 08-09-20.05 - عبدالرحمن 09/23/2008 2:44:23.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1256.1.1025.18.160 [GMT 3:00]
Running from: C:\Users\عبدالرحمن\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
E:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-08-22 to 2008-09-22 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-22 23:41 --------- d-----w C:\Users\عبدالرحمن\AppData\Roaming\DMCache
2008-09-22 23:38 --------- d-----w C:\Program Files\Internet Download Manager
2008-09-22 23:35 777,760 --sha-w C:\Windows\system32\drivers\fidbox.dat
2008-09-22 23:33 --------- d-----w C:\ProgramData\Kaspersky Lab
2008-09-22 23:31 9,224 --sha-w C:\Windows\system32\drivers\fidbox.idx
2008-09-22 23:31 122,912 --sha-w C:\Windows\system32\drivers\fidbox2.dat
2008-09-22 23:31 1,500 --sha-w C:\Windows\system32\drivers\fidbox2.idx
2008-09-22 23:00 66,144 ----a-w C:\Windows\system32\drivers\snapman.sys
2008-09-22 23:00 371,200 ----a-w C:\Windows\System32\autoprnt.exe
2008-09-22 23:00 37,888 ----a-w C:\Windows\System32\setupnt.dll
2008-09-22 23:00 102,400 ----a-w C:\Windows\System32\snapapi.dll
2008-09-22 23:00 --------- d-----w C:\Program Files\Common Files\Acronis
2008-09-22 23:00 --------- d-----w C:\Program Files\Acronis
2008-09-22 22:49 --------- d-----w C:\Users\عبدالرحمن\AppData\Roaming\IDM
2008-09-22 21:37 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-22 21:24 96,976 ----a-w C:\Windows\system32\drivers\klin.dat
2008-09-22 21:00 87,855 ----a-w C:\Windows\system32\drivers\klick.dat
2008-09-22 20:59 --------- d-----w C:\Program Files\Kaspersky Lab
2008-09-22 20:54 --------- d-----w C:\ProgramData\Kaspersky Lab Setup Files
2008-09-22 20:27 53,448 ----a-w C:\Windows\System32\wuauclt.exe
2008-09-22 20:27 45,768 ----a-w C:\Windows\System32\wups2.dll
2008-09-22 20:27 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
2008-09-22 20:27 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
2008-09-22 20:26 83,456 ----a-w C:\Windows\System32\wudriver.dll
2008-09-22 20:26 563,912 ----a-w C:\Windows\System32\wuapi.dll
2008-09-22 20:26 36,552 ----a-w C:\Windows\System32\wups.dll
2008-09-22 20:26 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-09-22 20:26 163,904 ----a-w C:\Windows\System32\wuwebv.dll
2008-09-22 20:17 --------- d-sh--w C:\ProgramData\قائمة ابدأ
2008-09-22 20:17 --------- d-sh--w C:\ProgramData\سطح المكتب
2008-07-29 17:21 218,376 ----a-w C:\Windows\System32\klogon.dll
2008-07-29 17:20 24,774 ----a-w C:\Windows\system32\drivers\klopp.dat
2008-07-09 14:34 206,256 ----a-w C:\Windows\System32\idmmbc.dll
2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [07/29/2008 08:20 PM 206088]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-373528825-3570736899-3151277766-1000]
"EnableNotificationsRef"=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\Windows\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [07/09/2008 06:28 PM 20496]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\Windows\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{160e3848-88e2-11dd-bf52-806e6f6e6963}]
\shell\AutoRun\command - F:\autorun.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [URL]http://www.gmer.net[/URL]
Rootkit scan 2008-09-23 02:47:27
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 09/23/2008 2:48:54
ComboFix-quarantined-files.txt 2008-09-22 23:48:44
Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application.
Post-Run: 1,242,136,576 bytes free
104 --- E O F --- 2008-09-22 21:08:30