ComboFix 08-10-07.06 - Abu Almohand 10/08/2008 13:05:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.549 [GMT 4:00]
Running from: F:\Documents and Settings\Abu Almohand\Desktop\ComboFix.exe
* Created a new restore point
[color=RED][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
D:\Autorun.inf
E:\Autorun.inf
F:\Documents and Settings\Abu Almohand\Local Settings\Temporary Internet Files\SuggestedSites.dat
F:\Documents and Settings\Flat\Local Settings\Temporary Internet Files\SuggestedSites.dat
F:\WINDOWS\IE4 Error Log.txt
F:\WINDOWS\system32\ALOAudioFile2.dll
F:\WINDOWS\system32\ALOAVIFile.dll
F:\WINDOWS\system32\ALOQuickTimeFile.dll
F:\WINDOWS\system32\ALOVideoCoreM.dll
F:\WINDOWS\system32\ALOWMAFile2.dll
F:\WINDOWS\system32\kakle.dll
F:\WINDOWS\system32\x64
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2008-09-08 to 2008-10-08 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-08 09:20 152,864 --sha-w F:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-08 09:20 13,560,096 --sha-w F:\WINDOWS\system32\drivers\fidbox.dat
2008-10-08 09:20 --------- d-----w F:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-10-08 09:20 --------- d-----w F:\Documents and Settings\Abu Almohand\Application Data\DMCache
2008-10-08 09:18 25,748 --sha-w F:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-08 09:18 202,328 --sha-w F:\WINDOWS\system32\drivers\fidbox.idx
2008-10-06 19:36 --------- d-----w F:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-06 19:33 --------- d-----w F:\Program Files\Google
2008-10-06 19:28 --------- d-----w F:\Documents and Settings\All Users\Application Data\PC Suite
2008-10-06 19:28 --------- d-----w F:\Documents and Settings\Abu Almohand\Application Data\PC Suite
2008-10-06 19:27 0 ---ha-w F:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-10-04 14:40 --------- d--h--w F:\Program Files\InstallShield Installation Information
2008-10-04 14:40 --------- d-----w F:\Program Files\Creative
2008-10-04 14:37 --------- d-----w F:\Program Files\Eidos Interactive
2008-10-04 13:02 --------- d-----w F:\Documents and Settings\Abu Almohand\Application Data\Ankh
2008-10-04 13:00 --------- d-----w F:\Program Files\Ankh
2008-10-03 20:01 --------- d-----w F:\Documents and Settings\Abu Almohand\Application Data\Roxio
2008-10-03 19:47 --------- d-----w F:\Program Files\Electronic Arts
2008-10-03 19:37 --------- d-----w F:\Program Files\Folderico
2008-10-03 19:28 --------- d-----w F:\Documents and Settings\LocalService\Application Data\Roxio
2008-10-03 14:52 --------- d-----w F:\Program Files\Elaborate Bytes
2008-10-03 12:49 --------- d-----w F:\Documents and Settings\Abu Almohand\Application Data\IDM
2008-10-03 12:43 107,888 ----a-w F:\WINDOWS\system32\CmdLineExt.dll
2008-10-03 12:28 --------- d--h--r F:\Documents and Settings\Abu Almohand\Application Data\SecuROM
2008-10-03 10:18 --------- d-----w F:\Documents and Settings\Abu Almohand\Application Data\Media Player Classic
2008-10-03 10:17 --------- d-----w F:\Documents and Settings\Abu Almohand\Application Data\Nokia Multimedia Player
2008-10-02 20:53 96,976 ----a-w F:\WINDOWS\system32\drivers\klin.dat
2008-10-02 20:53 87,855 ----a-w F:\WINDOWS\system32\drivers\klick.dat
2008-10-02 20:36 --------- d-----w F:\Program Files\Internet Download Manager
2008-10-02 20:11 --------- d-----w F:\Documents and Settings\Abu Almohand\Application Data\GARMIN
2008-10-02 08:46 --------- d-----w F:\Program Files\Retrospect
2008-10-02 08:45 339,968 ----a-w F:\WINDOWS\system32\WDBtnMgr.exe
2008-10-02 08:45 --------- d-----w F:\Program Files\Western Digital Technologies
2008-10-02 08:45 --------- d-----w F:\Program Files\Common Files\InstallShield
2008-10-02 07:13 --------- d-----w F:\Documents and Settings\Abu Almohand\Application Data\ACD Systems
2008-10-01 19:29 --------- d-----w F:\Program Files\Common Files\ACD Systems
2008-10-01 19:29 --------- d-----w F:\Program Files\ACD Systems
2008-10-01 19:29 --------- d-----w F:\Documents and Settings\All Users\Application Data\ACD Systems
2008-10-01 19:14 --------- d-----w F:\Documents and Settings\Abu Almohand\Application Data\DivX
2008-10-01 13:59 112,144 ----a-w F:\WINDOWS\system32\drivers\kl1.sys
2008-10-01 13:47 --------- d-----w F:\Program Files\mqreeb
2008-10-01 13:46 --------- d-----w F:\Program Files\Roxio
2008-10-01 13:46 --------- d-----w F:\Program Files\Common Files\SureThing Shared
2008-10-01 13:44 --------- d-----w F:\Program Files\Common Files\Roxio Shared
2008-10-01 13:43 --------- d-----w F:\Program Files\Common Files\Sonic Shared
2008-10-01 13:43 --------- d-----w F:\Documents and Settings\All Users\Application Data\Roxio
2008-10-01 13:39 --------- d-----w F:\Program Files\Common Files\Nero
2008-10-01 13:39 --------- d-----w F:\Documents and Settings\All Users\Application Data\Sonic
2008-10-01 13:34 --------- d-----w F:\Program Files\Kaspersky Lab
2008-10-01 13:33 --------- d-----w F:\Program Files\Nokia
2008-10-01 13:33 --------- d-----w F:\Program Files\DIFX
2008-10-01 13:33 --------- d-----w F:\Program Files\Common Files\PCSuite
2008-10-01 13:33 --------- d-----w F:\Program Files\Common Files\Nokia
2008-10-01 13:33 --------- d-----w F:\Documents and Settings\Abu Almohand\Application Data\Nokia
2008-10-01 13:32 --------- d-----w F:\Program Files\PC Connectivity Solution
2008-10-01 13:32 --------- d-----w F:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-01 13:30 --------- d-----w F:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-01 13:28 --------- d-----w F:\Program Files\The converter
2008-10-01 13:28 --------- d-----w F:\Program Files\MSBuild
2008-10-01 13:28 --------- d-----w F:\Program Files\Microsoft Works
2008-10-01 13:27 90,112 ----a-w F:\WINDOWS\system32\ALOAudioFormatSettings3.dll
2008-10-01 13:27 780,288 ----a-w F:\WINDOWS\system32\ALOVideoCompress.dll
2008-10-01 13:27 778,240 ----a-w F:\WINDOWS\system32\ALOAudioCompress2.dll
2008-10-01 13:27 215,552 ----a-w F:\WINDOWS\system32\ALOWMVFile.dll
2008-10-01 13:27 2,846,720 ----a-w F:\WINDOWS\system32\ALOAudioCompress3.dll
2008-10-01 13:27 188,416 ----a-w F:\WINDOWS\system32\ALOVideoFile.dll
2008-10-01 13:27 1,245,184 ----a-w F:\WINDOWS\system32\bkll.dll
2008-10-01 13:27 --------- d-----w F:\Program Files\Microsoft.NET
2008-10-01 13:27 --------- d-----w F:\Program Files\Arabic_video
2008-10-01 13:27 --------- d-----w F:\Documents and Settings\All Users\Application Data\Installations
2008-10-01 13:25 --------- d-----w F:\Program Files\Microsoft Visual Studio 8
2008-10-01 13:18 --------- d-----w F:\Program Files\Motorola
2008-10-01 13:18 --------- d-----w F:\Program Files\McAfee
2008-10-01 13:18 --------- d-----w F:\Documents and Settings\All Users\Application Data\McAfee
2008-10-01 12:59 --------- d-----w F:\Program Files\Hewlett-Packard
2008-10-01 12:58 0 ---ha-w F:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-01 12:58 0 ---ha-w F:\WINDOWS\system32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
2008-10-01 12:56 21,361 ----a-w F:\WINDOWS\system32\drivers\AegisP.sys
2008-10-01 12:56 21,361 ----a-w F:\WINDOWS\AegisP.sys
2008-10-01 12:56 --------- d-----w F:\Documents and Settings\NetworkService\Application Data\Intel
2008-10-01 12:56 --------- d-----w F:\Documents and Settings\LocalService\Application Data\Intel
2008-10-01 12:56 --------- d-----w F:\Documents and Settings\Flat\Application Data\Intel
2008-10-01 12:56 --------- d-----w F:\Documents and Settings\Abu Almohand\Application Data\Intel
2008-10-01 12:55 --------- d-----w F:\Program Files\Intel
2008-10-01 12:55 --------- d-----w F:\Documents and Settings\All Users\Application Data\Intel
2008-10-01 12:52 --------- d-----w F:\Program Files\Realtek
2008-10-01 12:51 --------- d-----w F:\Documents and Settings\Abu Almohand\Application Data\InstallShield
2008-10-01 12:47 319,488 ----a-w F:\WINDOWS\HideWin.exe
2008-10-01 06:45 --------- d-----w F:\Program Files\Real_SC
2008-10-01 05:54 --------- d-----w F:\Program Files\Golden Al-Wafi Translator
2008-10-01 05:51 73,216 ----a-w F:\WINDOWS\ST6UNST.EXE
2008-10-01 05:51 172,032 ------w F:\WINDOWS\Setup1.exe
2008-10-01 05:50 --------- d-----w F:\Program Files\Common Files\Adobe
2008-10-01 05:45 --------- d-----w F:\Program Files\Windows Media Connect 2
2008-10-01 05:43 --------- d-----w F:\Program Files\K-Lite Codec Pack
2008-10-01 05:41 --------- d-----w F:\Program Files\DivX
2008-10-01 05:36 --------- d-----w F:\Program Files\Common Files\xing shared
2008-10-01 05:36 --------- d-----w F:\Program Files\Common Files\Real
2008-10-01 05:35 499,712 ----a-w F:\WINDOWS\system32\msvcp71.dll
2008-10-01 05:35 348,160 ----a-w F:\WINDOWS\system32\msvcr71.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="F:\WINDOWS\system32\ctfmon.exe" [08/03/2004 11:56 PM 15360]
"PC Suite Tray"="F:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [04/16/2008 12:53 PM 1079808]
"IDMan"="F:\Program Files\Internet Download Manager\IDMan.exe" [05/05/2008 06:00 PM 2594224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="F:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [01/12/2007 02:36 PM 827392]
"McAfeeUpdaterUI"="F:\Program Files\McAfee\Common Framework\UdaterUI.exe" [11/17/2006 01:39 PM 136768]
"SunJavaUpdateSched"="F:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM 144784]
"TkBellExe"="F:\Program Files\Common Files\Real\Update_OB\realsched.exe" [10/01/2008 09:35 AM 185896]
"Adobe Reader Speed Launcher"="F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 03:06 AM 40048]
"IntelZeroConfig"="F:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [10/08/2007 02:18 PM 995328]
"IntelWireless"="F:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [10/08/2007 02:13 PM 1101824]
"QlbCtrl"="F:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [12/06/2007 02:13 PM 202032]
"hpWirelessAssistant"="F:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [10/03/2007 03:15 PM 480560]
"SMSERIAL"="F:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [10/10/2006 12:43 AM 729088]
"GrooveMonitor"="F:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM 31016]
"IgfxTray"="F:\WINDOWS\system32\igfxtray.exe" [12/19/2007 11:08 AM 135168]
"HotKeysCmds"="F:\WINDOWS\system32\hkcmd.exe" [12/19/2007 11:08 AM 159744]
"Persistence"="F:\WINDOWS\system32\igfxpers.exe" [12/19/2007 11:07 AM 131072]
"VirtualCloneDrive"="F:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [04/29/2006 05:21 PM 94208]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 12:56 AM 110592 F:\WINDOWS\system32\bthprops.cpl]
"RTHDCPL"="RTHDCPL.EXE" [02/19/2008 03:34 PM 16858112 F:\WINDOWS\RTHDCPL.exe]
"WD Button Manager"="WDBtnMgr.exe" [10/02/2008 12:45 PM 339968 F:\WINDOWS\system32\WDBtnMgr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [08/22/2008 03:06 AM 128512 F:\WINDOWS\system32\advpack.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= yv12vfw.dll
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"F:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"F:\\Program Files\\MSN Messenger\\livecall.exe"=
"F:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"F:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"F:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R3 klim5;Kaspersky Anti-Virus NDIS Filter;F:\WINDOWS\system32\DRIVERS\klim5.sys [12/13/2007 01:28 PM 24592]
S2 FAH@D:+Downloads+FAH504-Console.exe;FAH@D:+Downloads+FAH504-Console.exe;D:\Downloads\FAH504-Console.exe [ ]
S3 p2pgasvc;Peer Networking Group Authentication;F:\WINDOWS\system32\svchost.exe [08/03/2004 11:56 PM 14336]
S3 p2pimsvc;Peer Networking Identity Manager;F:\WINDOWS\system32\svchost.exe [08/03/2004 11:56 PM 14336]
S3 p2psvc;Peer Networking;F:\WINDOWS\system32\svchost.exe [08/03/2004 11:56 PM 14336]
S3 PNRPSvc;Peer Name Resolution Protocol;F:\WINDOWS\system32\svchost.exe [08/03/2004 11:56 PM 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
s of the 'Scheduled Tasks' folder
2008-10-08 F:\WINDOWS\Tasks\User_Feed_Synchronization-{086EE5BF-19E9-4D3C-84C8-F1F816A2257E}.job
- F:\WINDOWS\system32\msfeedssync.exe [08/22/2008 03:05 AM]
2008-10-08 F:\WINDOWS\Tasks\User_Feed_Synchronization-{14D37422-6171-4F58-A5AB-0ED5FBA05F06}.job
- F:\WINDOWS\system32\msfeedssync.exe [08/22/2008 03:05 AM]
2008-10-08 F:\WINDOWS\Tasks\User_Feed_Synchronization-{4C10AAA7-D81B-42B4-89B1-5C2DCBEB4C33}.job
- F:\WINDOWS\system32\msfeedssync.exe [08/22/2008 03:05 AM]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - F:\Documents and Settings\Abu Almohand\Application Data\Mozilla\Firefox\Profiles\nc89fsrt.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.com
FF -: plugin - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
FF -: plugin - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
FF -: plugin - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF -: plugin - F:\Program Files\DivX\DivX Uploader\npUpload.dll
FF -: plugin - F:\Program Files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 13:20:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
"ImagePath"="F:\Program Files\Intel\Wireless\Bin\EvtEng.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FAH@D:+Downloads+FAH504-Console.exe]
.
------------------------ Other Running Processes ------------------------
.
F:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
F:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
F:\Program Files\McAfee\Common Framework\FrameworkService.exe
F:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
F:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
F:\WINDOWS\system32\tcpsvcs.exe
F:\Program Files\McAfee\Common Framework\naPrdMgr.exe
F:\WINDOWS\system32\wscntfy.exe
F:\Program Files\McAfee\Common Framework\Mctray.exe
F:\WINDOWS\system32\rundll32.exe
F:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
F:\WINDOWS\system32\igfxsrvc.exe
F:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
F:\Program Files\PC Connectivity Solution\ServiceLayer.exe
F:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
F:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
F:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
F:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
F:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 10/08/2008 13:24:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-08 09:23:59
Pre-Run: 11,119,980,544 bytes free
Post-Run: 11,216,740,352 bytes free
257