ComboFix 08-10-18.03 - S.M 10/19/2008 11:49:14.2 - NTFSx86[/COLOR]
[COLOR=purple]Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.142 [GMT 3:00][/COLOR]
[COLOR=purple]Running from: C:\Documents and Settings\S.M\Desktop\ComboFix.exe[/COLOR]
[COLOR=purple] * Created a new restore point[/COLOR]
[B][COLOR=purple]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/COLOR][/B]
[COLOR=purple].[/COLOR]
[COLOR=purple]((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]C:\Documents and Settings\S.M\Application Data\tazebama[/COLOR]
[COLOR=purple]C:\WINDOWS\system32\dao350.dll[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]((((((((((((((((((((((((( Files Created from 2008-09-19 to 2008-10-19 )))))))))))))))))))))))))))))))[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]No new files created in this timespan[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple](((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]2008-10-19 09:00 8,273,696 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat[/COLOR]
[COLOR=purple]2008-10-19 08:59 1,007,904 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat[/COLOR]
[COLOR=purple]2008-10-19 08:59 --------- d-----w C:\Documents and Settings\S.M\Application Data\Orbit[/COLOR]
[COLOR=purple]2008-10-19 08:52 95,468 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx[/COLOR]
[COLOR=purple]2008-10-19 08:52 111,764 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx[/COLOR]
[COLOR=purple]2008-10-19 08:47 --------- d-----w C:\Program Files\Orbitdownloader[/COLOR]
[COLOR=purple]2008-10-19 08:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab[/COLOR]
[COLOR=purple]2008-10-18 03:48 18,217 --sh--r C:\WINDOWS\system32\.vbe[/COLOR]
[COLOR=purple]2008-10-18 00:16 359,040 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys[/COLOR]
[COLOR=purple]2008-10-18 00:15 --------- d-----w C:\Documents and Settings\S.M\Application Data\GrabPro[/COLOR]
[COLOR=purple]2008-10-15 23:51 --------- d-----w C:\Program Files\My Drivers[/COLOR]
[COLOR=purple]2008-10-15 23:10 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP[/COLOR]
[COLOR=purple]2008-10-15 22:28 --------- d-----w C:\Program Files\Nsasoft[/COLOR]
[COLOR=purple]2008-10-15 22:22 --------- d-----w C:\Program Files\Common Files\Real[/COLOR]
[COLOR=purple]2008-10-15 08:55 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]------- Sigcheck -------[/COLOR]
[COLOR=purple]10/18/2008 03:16 AM 359040 c1783498edb152656303b5d5bcabd86c C:\WINDOWS\system32\dllcache\tcpip.sys[/COLOR]
[COLOR=purple]10/18/2008 03:16 AM 359040 c1783498edb152656303b5d5bcabd86c C:\WINDOWS\system32\drivers\tcpip.sys[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]*Note* empty entries & legit default entries are not shown [/COLOR]
[COLOR=purple]REGEDIT4[/COLOR]
[COLOR=purple][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][/COLOR]
[COLOR=purple]"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [04/11/2006 05:52 PM 1409024][/COLOR]
[COLOR=purple]"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 03:56 AM 15360][/COLOR]
[COLOR=purple][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][/COLOR]
[COLOR=purple]"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [02/10/2004 08:55 PM 155648][/COLOR]
[COLOR=purple]"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [02/10/2004 08:51 PM 118784][/COLOR]
[COLOR=purple]"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [05/20/2004 02:57 PM 98304][/COLOR]
[COLOR=purple]"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [05/20/2004 02:57 PM 532480][/COLOR]
[COLOR=purple]"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 10:50 PM 155648][/COLOR]
[COLOR=purple]"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [02/19/2006 02:41 AM 49152][/COLOR]
[COLOR=purple]"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [04/26/2006 08:29 AM 237568][/COLOR]
[COLOR=purple]"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM 31016][/COLOR]
[COLOR=purple]"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [01/30/2007 10:02 AM 200768][/COLOR]
[COLOR=purple]"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 03:56 AM 110592 C:\WINDOWS\system32\bthprops.cpl][/COLOR]
[COLOR=purple][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run][/COLOR]
[COLOR=purple]"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 03:56 AM 15360][/COLOR]
[COLOR=purple][HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run][/COLOR]
[COLOR=purple]"ACER"=".vbe" [10/18/2008 06:48 AM 18217 C:\WINDOWS\system32\.vbe][/COLOR]
[COLOR=purple]C:\Documents and Settings\All Users\Start Menu\Programs\Startup\[/COLOR]
[COLOR=purple]HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472][/COLOR]
[COLOR=purple]Orbit.lnk - C:\Program Files\Orbitdownloader\orbitdm.exe [2008-10-18 1707208][/COLOR]
[COLOR=purple][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer][/COLOR]
[COLOR=purple]"NoUserNameInStartMenu"= 0 (0x0)[/COLOR]
[COLOR=purple][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32][/COLOR]
[COLOR=purple]"msacm.divxa32"= msaud32_divx.acm[/COLOR]
[COLOR=purple]"msacm.vivog723"= vivog723.acm[/COLOR]
[COLOR=purple]"VIDC.VIVO"= ivvideo.dll[/COLOR]
[COLOR=purple]"VIDC.TR20"= tr2032.dll[/COLOR]
[COLOR=purple][HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa][/COLOR]
[COLOR=purple]Authentication Packages REG_MULTI_SZ msv1_0 nwprovau[/COLOR]
[COLOR=purple][HKEY_LOCAL_MACHINE\software\microsoft\security center][/COLOR]
[COLOR=purple]"AntiVirusOverride"=dword:00000001[/COLOR]
[COLOR=purple][HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus][/COLOR]
[COLOR=purple]"DisableMonitoring"=dword:00000001[/COLOR]
[COLOR=purple][HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List][/COLOR]
[COLOR=purple]"%windir%\\system32\\sessmgr.exe"=[/COLOR]
[COLOR=purple]"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=[/COLOR]
[COLOR=purple]"C:\\Program Files\\MSN Messenger\\msncall.exe"=[/COLOR]
[COLOR=purple]"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=[/COLOR]
[COLOR=purple]"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=[/COLOR]
[COLOR=purple]"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=[/COLOR]
[COLOR=purple]"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=[/COLOR]
[COLOR=purple]"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=[/COLOR]
[COLOR=purple]R1 SMBHC;Microsoft SM Bus Host Controller Driver;C:\WINDOWS\system32\DRIVERS\SMBHC.sys [08/17/2001 04:57 PM 6784][/COLOR]
[COLOR=purple]R3 SMBBATT;Microsoft Smart Battery Driver;C:\WINDOWS\system32\DRIVERS\SMBBATT.sys [08/04/2004 02:07 AM 16128][/COLOR]
[COLOR=purple]S2 A4C875E3;A4C875E3;C:\WINDOWS\system32\F0C5977E.EXE [ ][/COLOR]
[COLOR=purple][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ad47a42d-4eed-11c6-a924-000e35296a02}][/COLOR]
[COLOR=purple]\Shell\Auto\command - F:\auto.exe[/COLOR]
[COLOR=purple]\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe[/COLOR]
[COLOR=purple]\Shell\explore\Command - F:\t.com[/COLOR]
[COLOR=purple]\Shell\open\Command - F:\t.com[/COLOR]
[COLOR=purple][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce3d18ee-38fd-11da-a977-000e35296a02}][/COLOR]
[COLOR=purple]\Shell\Auto\command - E:\auto.exe[/COLOR]
[COLOR=purple]\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe[/COLOR]
[COLOR=purple]\Shell\open\command - wscript.exe .\.vbs[/COLOR]
[COLOR=purple][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f396ead7-4fbf-11c6-a92c-000e35296a02}][/COLOR]
[COLOR=purple]\Shell\AutoRun\command - F:\zPharaoh.exe[/COLOR]
[COLOR=purple]\Shell\explore\command - F:\zPharaoh.exe[/COLOR]
[COLOR=purple]\Shell\open\command - F:\zPharaoh.exe[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]- - - - ORPHANS REMOVED - - - -[/COLOR]
[COLOR=purple]HKLM-Run-zyz1 - c:\zyz_auto_killer\run2.exe[/COLOR]
[COLOR=purple] [/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]------- Supplementary Scan -------[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/[/COLOR]
[COLOR=purple]O8 -: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/201[/COLOR]
[COLOR=purple]O8 -: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/204[/COLOR]
[COLOR=purple]O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000[/COLOR]
[COLOR=purple]O8 -: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/203[/COLOR]
[COLOR=purple]O8 -: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/202[/COLOR]
[COLOR=purple]O8 -: ت&صدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000[/COLOR]
[COLOR=purple]O16 -: Microsoft XML Parser for Java - [/COLOR][URL="file://C:\WINDOWS\Java\classes\xmldso.cab"][COLOR=purple]file://C:\WINDOWS\Java\classes\xmldso.cab[/COLOR][/URL]
[COLOR=purple]C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]**************************************************************************[/COLOR]
[COLOR=purple]catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [/COLOR][URL="http://www.gmer.net"][COLOR=purple]http://www.gmer.net[/COLOR][/URL]
[COLOR=purple]Rootkit scan 2008-10-19 11:57:06[/COLOR]
[COLOR=purple]Windows 5.1.2600 Service Pack 2 NTFS[/COLOR]
[COLOR=purple]scanning hidden processes ... [/COLOR]
[COLOR=purple]scanning hidden autostart entries ...[/COLOR]
[COLOR=purple]scanning hidden files ... [/COLOR]
[COLOR=purple]scan completed successfully[/COLOR]
[COLOR=purple]hidden files: 0[/COLOR]
[COLOR=purple]**************************************************************************[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]------------------------ Other Running Processes ------------------------[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]C:\WINDOWS\system32\HPZipm12.exe[/COLOR]
[COLOR=purple]C:\WINDOWS\system32\rundll32.exe[/COLOR]
[COLOR=purple]C:\Program Files\Orbitdownloader\orbitnet.exe[/COLOR]
[COLOR=purple]C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe[/COLOR]
[COLOR=purple]C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe[/COLOR]
[COLOR=purple]C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE[/COLOR]
[COLOR=purple]C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]**************************************************************************[/COLOR]
[COLOR=purple].[/COLOR]
[COLOR=purple]Completion time: 10/19/2008 12:03:20 - machine was rebooted [S.M][/COLOR]
[COLOR=purple]ComboFix-quarantined-files.txt 2008-10-19 09:03:05[/COLOR]
[COLOR=purple]Pre-Run: 12,500,905,984 bytes free[/COLOR]
[COLOR=purple]Post-Run: 12,695,236,608 bytes free[/COLOR]
[COLOR=purple]144[/COLOR]
[COLOR=purple]