ComboFix 08-10-17.01 - - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.555 [GMT 3:00]
Running from: C:\Documents and Settings\m\My Documents\Downloads\Programs\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-09-18 to 2008-10-18 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-18 13:30 20,160 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-18 13:30 2,308,128 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-18 13:30 --------- d-----w C:\Documents and Settings\منصور\Application Data\DMCache
2008-10-18 11:34 --------- dc----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-10-18 11:32 344,096 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-18 11:32 3,304 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-17 20:17 --------- d-----w C:\Program Files\MSXML 4.0
2008-10-17 17:24 --------- d-----w C:\Program Files\SWiSH Max2
2008-10-17 13:56 --------- d-----w C:\Program Files\Fisher
2008-10-17 12:22 --------- dc----w C:\Documents and Settings\All Users\Application Data\ashampoo
2008-10-17 12:22 --------- d-----w C:\Program Files\Ashampoo
2008-10-17 12:12 --------- d-----w C:\Program Files\Internet Download Manager
2008-10-17 09:04 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-10-17 08:56 --------- dc----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-10-17 08:56 --------- d-----w C:\Documents and Settings\منصور\Application Data\PC Suite
2008-10-17 08:22 --------- dc----w C:\Documents and Settings\All Users\Application Data\Nokia
2008-10-17 08:20 --------- dc----w C:\Documents and Settings\All Users\Application Data\Installations
2008-10-17 08:19 --------- d-----w C:\Program Files\Nokia
2008-10-17 08:17 --------- d-----w C:\Program Files\MSXML 6.0
2008-10-17 08:16 --------- d-----w C:\Program Files\Common Files\Nokia
2008-10-17 07:51 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-10-17 07:47 --------- d-----w C:\Program Files\DIFX
2008-10-17 07:46 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-10-17 07:41 --------- d-----w C:\Program Files\Back2Life 2.6.1
2008-10-17 07:26 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-17 07:26 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-10-17 06:58 --------- d-----w C:\Program Files\SlySoft
2008-10-17 06:24 --------- d-----w C:\Documents and Settings\منصور\Application Data\ACD Systems
2008-10-17 05:45 --------- d-----w C:\Program Files\Google
2008-10-16 20:19 --------- d-----w C:\Documents and Settings\منصور\Application Data\IDM
2008-10-16 19:15 --------- d-----w C:\Program Files\Common Files\xing shared
2008-10-16 19:15 --------- d-----w C:\Program Files\Common Files\Real
2008-10-16 12:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-16 12:12 --------- d-----w C:\Program Files\MSBuild
2008-10-16 12:12 --------- d-----w C:\Program Files\Microsoft Works
2008-10-16 08:39 160,545 ----a-w C:\WINDOWS\Sqirlz Water Reflections Uninstaller.exe
2008-10-16 08:39 --------- d-----w C:\Program Files\Sqirlz Water Reflections
2008-10-16 08:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Torrent2Exe
2008-10-16 08:25 --------- d-----w C:\Program Files\Unlocker
2008-10-16 08:24 73,216 ------w C:\WINDOWS\ST6UNST.EXE
2008-10-16 08:24 3,051,520 ------w C:\WINDOWS\Setup1.exe
2008-10-16 07:01 --------- d-----w C:\Documents and Settings\منصور\Application Data\CyberLink
2008-10-16 05:24 --------- d-----w C:\Program Files\Sun
2008-10-16 05:24 --------- d-----w C:\Program Files\Java
2008-10-16 05:18 --------- d-----w C:\Program Files\Common Files\Java
2008-10-16 04:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2008-10-15 22:12 --------- d-----w C:\Documents and Settings\منصور\Application Data\Talkback
2008-10-15 21:49 --------- d-----w C:\Program Files\Common Files\Adobe
2008-10-15 21:34 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-10-15 21:34 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-10-15 21:19 --------- d-----w C:\Program Files\Kaspersky Lab
2008-10-15 21:15 --------- dc----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-15 21:12 --------- d-----w C:\Program Files\Hewlett-Packard
2008-10-15 21:11 --------- d-----w C:\Program Files\MSN Messenger
2008-10-15 21:02 155,995 ----a-w C:\WINDOWS\java\Packages\E6SC1V53.ZIP
2008-10-15 21:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-15 21:02 --------- d-----w C:\Documents and Settings\منصور\Application Data\Share-to-Web Upload Folder
2008-10-15 20:57 --------- d-----w C:\Program Files\Common Files\Ahead
2008-10-15 20:57 --------- d-----w C:\Program Files\Ahead
2008-10-15 20:17 --------- dc----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-10-15 20:17 --------- d-----w C:\Program Files\Real
2008-10-15 20:15 --------- d-----w C:\Program Files\CyberLink
2008-10-15 20:15 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-15 20:13 --------- d-----w C:\Program Files\JetAudio
2008-10-15 20:13 --------- d-----w C:\Program Files\Common Files\COWON
2008-10-15 20:12 --------- dc----w C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-10-15 20:12 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-10-15 20:12 --------- d-----w C:\Program Files\ACD Systems
2008-10-15 19:58 --------- d-----w C:\Program Files\Realtek
2008-10-15 19:58 --------- d-----w C:\Documents and Settings\منصور\Application Data\InstallShield
2008-10-15 19:54 --------- d-----w C:\Program Files\Intel
2008-10-15 19:46 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-15 15:37 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-12 10:44 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-20 05:36 657,920 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:42 2,137,600 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:42 2,017,280 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2001-09-19 12:00 95,024 --sh--w C:\WINDOWS\twain.dll
2004-08-03 21:55 50,688 --sh--w C:\WINDOWS\twain_32.dll
2004-08-03 21:55 1,028,096 --sh--w C:\WINDOWS\system32\mfc42.dll
2004-08-03 21:55 54,784 --sh--w C:\WINDOWS\system32\msvcirt.dll
2004-08-03 21:55 413,696 --sh--w C:\WINDOWS\system32\msvcp60.dll
2004-08-03 21:55 343,040 --sh--w C:\WINDOWS\system32\msvcrt.dll
2004-08-03 21:55 553,472 --sh--w C:\WINDOWS\system32\oleaut32.dll
2004-08-03 21:55 83,456 --sh--w C:\WINDOWS\system32\olepro32.dll
2004-08-03 21:56 11,776 --sh--w C:\WINDOWS\system32\regsvr32.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [01/19/2007 12:55 PM 5674352]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [09/12/2008 01:44 PM 2606512]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [10/16/2008 11:34 PM 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [11/28/2005 08:55 AM 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [11/28/2005 08:52 AM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [11/28/2005 08:55 AM 118784]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [11/02/2004 08:24 PM 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 10:50 AM 155648]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [07/03/2001 09:11 AM 57344]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [10/16/2008 12:20 AM 29744]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM 144784]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [09/07/2006 08:19 PM 15872]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM 31016]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [10/16/2008 10:14 PM 185872]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [09/03/2004 12:57 AM 57344]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"SkyTel"="SkyTel.EXE" [05/16/2006 01:04 PM 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [11/14/2006 12:21 PM 16270848 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
C:\Documents and Settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-10-15 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-10-15 122880]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [03/25/2008 08:07 PM 24592]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [10/16/2008 12:20 AM 29744]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [02/01/2008 04:17 PM 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [02/01/2008 04:17 PM 8320]
*Newly Created Service* - CATCHME
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\m\Application Data\Mozilla\Firefox\Profiles\wt45e2ge.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-18 16:31:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 10/18/2008 16:33:56
ComboFix-quarantined-files.txt 2008-10-18 13:33:31
ComboFix2.txt 2008-10-18 11:40:20
Pre-Run: 37,609,033,728 bytes free
Post-Run: 37,599,846,400 bytes free
174 --- E O F --- 2008-10-17 20:17:21