هذي مال الشي الاحمر الي عطيتني اياه
ComboFix 08-10-15.08 - user 2008-10-16 20:59:07.13 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.973.1033.18.1617 [GMT 3:00]
Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\9.cmd
C:\WINDOWS\system32\ckvo.exe
C:\WINDOWS\system32\ckvo0.dll
C:\WINDOWS\system32\ckvo1.dll
D:\9.cmd
.
((((((((((((((((((((((((( Files Created from 2008-09-16 to 2008-10-16 )))))))))))))))))))))))))))))))
.
2008-10-16 19:29 . 2008-10-16 19:29 96,645 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-10-16 19:29 . 2008-10-16 19:29 87,941 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-10-16 19:28 . 2008-10-16 19:28 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-10-16 19:28 . 2008-10-16 20:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-10-16 19:28 . 2008-10-16 20:58 1,150,496 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-16 19:28 . 2008-10-16 20:58 376,864 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-16 19:28 . 2008-10-16 20:58 11,116 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-16 19:28 . 2008-10-16 20:58 2,368 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-15 20:00 . 2008-10-15 20:01 102,278 -r-hs---- C:\pnt.com
2008-10-07 19:51 . 2008-10-07 19:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
2008-09-25 23:25 . 2008-09-25 23:26 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-09-20 21:36 . 2008-04-17 13:12 107,368 --a------ C:\WINDOWS\system32\GEARAspi.dll
2008-09-20 21:36 . 2008-04-17 13:12 15,464 --a------ C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2008-09-20 21:35 . 2008-09-20 21:36 <DIR> d-------- C:\Program Files\iTunes
2008-09-20 21:35 . 2008-09-20 21:35 <DIR> d-------- C:\Program Files\iPod
2008-09-20 21:35 . 2008-09-20 21:35 <DIR> d-------- C:\Program Files\Bonjour
2008-09-20 21:35 . 2008-09-20 21:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-20 21:33 . 2008-09-20 21:34 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-09-20 21:33 . 2008-09-20 21:33 <DIR> d-------- C:\Program Files\Apple Software Update
2008-09-17 22:19 . 2008-09-17 22:19 172,032 --------- C:\WINDOWS\Setup1.exe
2008-09-17 22:19 . 2008-09-17 22:19 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-16 18:01 --------- d-----w C:\Documents and Settings\user\Application Data\DMCache
2008-10-16 16:39 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-14 16:24 --------- d-----w C:\Documents and Settings\user\Application Data\AvaFind Data
2008-10-05 16:27 --------- d-----w C:\Program Files\Google
2008-09-20 18:36 --------- d-----w C:\Documents and Settings\user\Application Data\Apple Computer
2008-09-20 18:35 --------- d-----w C:\Program Files\QuickTime
2008-09-20 18:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-14 19:14 --------- d-----w C:\Program Files\Total Video Converter
2008-09-14 06:05 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-13 19:31 --------- d-----w C:\Documents and Settings\user\Application Data\Vso
2008-09-07 20:12 --------- d-----w C:\Program Files\FairStars Audio Converter
2008-09-07 18:56 --------- d-----w C:\Program Files\AutoPlay Media Studio 6.0 Trial
2008-09-07 18:55 --------- d-----w C:\Program Files\bahrainevents
2008-09-05 19:52 --------- d-----w C:\Program Files\7-Zip
2008-09-02 17:40 --------- d-----w C:\Documents and Settings\user\Application Data\Skype
2008-09-02 17:38 --------- d-----w C:\Documents and Settings\user\Application Data\skypePM
2008-09-02 17:33 --------- d-----w C:\Program Files\Hide IP Platinum
2008-09-02 17:30 --------- d-----w C:\Documents and Settings\user\Application Data\Hide IP NG
2008-09-01 18:43 --------- d-----w C:\Program Files\CEDP Stealer 6.0 for Messenger
2008-08-29 07:18 87,336 ----a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 06:53 61,440 ----a-w C:\WINDOWS\system32\dnssd.dll
2008-08-26 18:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-26 18:18 --------- d-----w C:\Program Files\DrWeb
2008-08-26 17:58 77,824 ----atw C:\WINDOWS\system32\DRWEBSP.DLL
2008-08-24 17:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-08-22 17:44 2,342 ----a-w C:\WINDOWS\system32\tmp.reg
2008-08-21 20:41 87,552 ----a-w C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-08-18 09:19 82,432 ----a-w C:\WINDOWS\system32\404Fix.exe
2008-08-17 18:03 --------- d-----w C:\Documents and Settings\user\Application Data\onOne Software
2008-08-17 18:02 --------- d-----w C:\Program Files\Common Files\onOne Software Shared
2008-08-17 18:01 --------- d-----w C:\Program Files\onOne Software
2008-08-14 18:52 82,432 ----a-w C:\WINDOWS\system32\IEDFix.C.exe
2008-08-10 14:02 90,112 ----a-w C:\WINDOWS\system32\agsaami.dll
2008-08-10 14:02 753,664 ----a-w C:\WINDOWS\system32\agsaamg.dll
2008-08-10 14:02 626,688 ----a-w C:\WINDOWS\system32\agsaamh.dll
2008-08-10 14:02 544,256 ----a-w C:\WINDOWS\system32\agsaamd.dll
2008-08-10 14:02 538,624 ----a-w C:\WINDOWS\system32\agsaamb.dll
2008-08-10 14:02 372,736 ----a-w C:\WINDOWS\system32\agsaamc.dll
2008-08-10 14:02 331,776 ----a-w C:\WINDOWS\system32\agsaama.dll
2008-08-10 14:02 237,568 ----a-w C:\WINDOWS\system32\lame_enc.dll
2008-08-10 14:02 2,846,720 ----a-w C:\WINDOWS\system32\agsaamj.dll
2008-08-10 14:01 90,112 ----a-w C:\WINDOWS\system32\ALOAudioFormatSettings3.dll
2008-08-10 14:01 780,288 ----a-w C:\WINDOWS\system32\ALOVideoCompress.dll
2008-08-10 14:01 778,240 ----a-w C:\WINDOWS\system32\ALOAudioCompress2.dll
2008-08-10 14:01 215,552 ----a-w C:\WINDOWS\system32\ALOWMVFile.dll
2008-08-10 14:01 2,846,720 ----a-w C:\WINDOWS\system32\ALOAudioCompress3.dll
2008-08-10 14:01 188,416 ----a-w C:\WINDOWS\system32\ALOVideoFile.dll
2008-08-10 14:01 1,245,184 ----a-w C:\WINDOWS\system32\bkll.dll
2008-08-09 19:45 344,064 ----a-w C:\WINDOWS\system32\dkll.dll
2008-08-09 19:45 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-08-09 19:45 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-08-09 19:45 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 19:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 19:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 19:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 19:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 19:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-13 16:07 47,360 ----a-w C:\Documents and Settings\user\Application Data\pcouffin.sys
2007-11-08 17:05 41,472 --sha-w C:\WINDOWS\system32\imapdb.dll
2007-11-08 17:05 438,272 --sha-w C:\WINDOWS\system32\imapdc.dll
2007-11-08 17:05 36,352 --sha-w C:\WINDOWS\system32\imapdd.dll
2007-11-08 17:05 99,840 --sha-w C:\WINDOWS\system32\imapde.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{d3095906-703f-42fa-85be-f2a060ad126c}"= "C:\Program Files\bahrainevents\tbbah0.dll" [2008-06-24 1569304]
[HKEY_CLASSES_ROOT\clsid\{d3095906-703f-42fa-85be-f2a060ad126c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{d3095906-703f-42fa-85be-f2a060ad126c}]
2008-06-24 23:17 1569304 --a------ C:\Program Files\bahrainevents\tbbah0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{d3095906-703f-42fa-85be-f2a060ad126c}"= "C:\Program Files\bahrainevents\tbbah0.dll" [2008-06-24 1569304]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D3095906-703F-42FA-85BE-F2A060AD126C}"= "C:\Program Files\bahrainevents\tbbah0.dll" [2008-06-24 1569304]
[HKEY_CLASSES_ROOT\clsid\{d3095906-703f-42fa-85be-f2a060ad126c}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-03-19 630784]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2007-06-20 800256]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-08-06 1667584]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-10-05 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-05-24 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-08 289576]
"LFAgent"="" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-02-28 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-10-09 610365]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvIcon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
--a------ 2008-06-11 22:43 640376 C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
--a------ 2008-06-12 02:25 37232 C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AvaFind]
--------- 2004-06-01 12:48 295936 C:\Program Files\AvaFind\AvaFind.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CacheBoost]
--a------ 2008-06-12 16:49 74480 C:\Program Files\Systweak\Systweak CacheBoost\trayicon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2004-12-27 22:14 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2006-02-28 15:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
-ra------ 2007-01-13 04:47 163840 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
-ra------ 2007-01-13 04:47 131072 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 2006-05-18 11:29 49152 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-08-06 21:09 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2008-08-06 21:10 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
-ra------ 2007-01-13 04:46 135168 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2005-12-07 22:57 30208 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-05-24 19:04 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Window Washer]
--a------ 2008-08-06 21:10 1109504 C:\Program Files\Webroot\Washer\wwDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2006-09-12 11:58 16264192 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-r------- 2006-05-16 13:04 2879488 C:\WINDOWS\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\IEPro\\MiniDM.exe"=
"C:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"C:\\Documents and Settings\\user\\Desktop\\أنا مسلمة\\ana-muslema\\Software\\Web\\Messenger\\Messenger.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R2 CacheBoost Service;CacheBoost Performance Optimizer and Tuner Service;C:\Program Files\Systweak\Systweak CacheBoost\cbsrv.exe [2008-06-12 187120]
R2 LF30FS;LF30FS;C:\Program Files\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [2004-11-19 101488]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 24592]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2007-06-08 27136]
S1 SABKUTIL;SABKUTIL;C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys [ ]
S3 AVPsys;AVPsys;C:\WINDOWS\system32\drivers\cdaudio.sys [2001-08-17 18688]
S3 ORITE;Mini-cam(SC120);C:\WINDOWS\system32\DRIVERS\pfc027.sys [2003-09-16 108092]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ac168bcb-9ac6-11dd-a5d8-0019664ced20}]
\Shell\AutoRun\command - F:\pnt.com
\Shell\explore\Command - F:\pnt.com
\Shell\open\Command - F:\pnt.com
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\9932lrp8.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1739886&SearchSource=3&q=
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-16 21:01:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-10-16 21:04:25
ComboFix-quarantined-files.txt 2008-10-16 18:03:23
ComboFix2.txt 2008-09-16 19:01:30
ComboFix3.txt 2008-08-21 14:57:33
ComboFix4.txt 2008-08-20 15:48:10
Pre-Run: 10,807,255,040 bytes free
Post-Run: 10,796,519,424 bytes free
241 --- E O F --- 2008-05-26 13:50:31