aky bad ma amlt takrer ma ak katb arabe lesh
ComboFix 08-10-30.04 - Administrator 10/30/2008 2:06:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.441 [GMT -8:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-30 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-30 10:08 93,216 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-30 10:08 2,071,584 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-30 08:55 --------- d-----w C:\Documents and Settings\Administrator\Application Data\cleaner
2008-10-30 02:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-10-29 22:01 29,516 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-29 22:01 11,936 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-29 19:02 --------- d-----w C:\Documents and Settings\Administrator\Application Data\U3
2008-10-27 20:54 --------- d-----w C:\Program Files\KingoOo Flash to Video Encoder
2008-10-24 12:16 --------- d-----w C:\Documents and Settings\Administrator\Application Data\GeoVid
2008-10-23 21:25 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-10-23 21:24 --------- d-----w C:\Program Files\Yahoo!
2008-10-23 14:09 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-10-23 14:09 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-10-23 14:09 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-10-22 00:22 --------- d-----w C:\Program Files\Image Converter .EXE
2008-10-22 00:21 --------- d-----w C:\Program Files\Common Files\SoftTech InterCorp
2008-10-22 00:18 --------- d-----w C:\Program Files\قاموس صخر الجديد
2008-10-21 22:06 --------- d-----w C:\Program Files\Ashampoo
2008-10-21 21:55 --------- d-----w C:\Program Files\Common Files\Adobe
2008-10-21 21:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-21 13:21 --------- d-s---r C:\Program Files\WinDriveGuard
2008-10-20 23:31 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-10-20 23:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-10-20 23:09 --------- d-----w C:\Program Files\Common Files\Motive
2008-10-20 23:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Motive
2008-10-20 18:21 --------- d-----w C:\Program Files\Kaspersky Lab
2008-10-20 18:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-20 18:18 --------- d-----w C:\Program Files\Nero
2008-10-20 18:18 --------- d-----w C:\Program Files\Common Files\Ahead
2008-10-20 18:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-10-20 18:15 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Yahoo!
2008-10-20 18:13 --------- d-----w C:\Program Files\Java
2008-10-20 18:13 --------- d-----w C:\Program Files\Common Files\Java
2008-10-20 18:12 155,995 ----a-w C:\WINDOWS\java\Packages\AQDRBB9N.ZIP
2008-10-20 18:11 --------- d-----w C:\Program Files\MSN Messenger
2008-10-20 18:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2008-10-20 18:09 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ACD Systems
2008-10-20 18:08 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-10-20 18:08 --------- d-----w C:\Program Files\ACD Systems
2008-10-20 18:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-10-20 18:02 --------- d-----w C:\Program Files\QuickTime
2008-10-20 18:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-10-20 18:00 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-10-20 18:00 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-10-20 18:00 --------- d-----w C:\Program Files\Real
2008-10-20 18:00 --------- d-----w C:\Program Files\Common Files\xing shared
2008-10-20 18:00 --------- d-----w C:\Program Files\Common Files\Real
2008-10-20 17:59 --------- d-----w C:\Program Files\Google
2008-10-20 17:59 --------- d-----w C:\Program Files\CyberLink
2008-10-20 17:50 --------- d-----w C:\Program Files\Microsoft.NET
2008-10-20 17:50 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-10-20 17:35 --------- d-----w C:\Program Files\S3
2008-10-20 17:33 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-20 17:30 --------- d-----w C:\Program Files\Intel
2008-10-20 17:28 --------- d-----w C:\Program Files\CONEXANT
2008-10-20 17:26 --------- d-----w C:\Program Files\Realtek
2008-10-20 17:23 --------- d-----w C:\Program Files\Realtek AC97
2008-10-20 17:23 --------- d-----w C:\Program Files\AvRack
2008-10-20 17:12 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-10-20 16:32 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 11:56 PM 15360]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [01/19/2007 11:54 AM 5674352]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [10/24/2006 03:10 PM 4662776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [10/20/2008 10:00 AM 185896]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/03/2004 11:56 PM 110592 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/03/2004 11:56 PM 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-10-21 113664]
DriveGuard.lnk - C:\Program Files\WinDriveGuard\DriveGuard.exe [2008-10-21 434353]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
--a------ 02/08/2008 05:36 PM 227856 C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
--------- 06/11/2005 06:51 PM 53248 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 12/16/2005 02:57 AM 94208 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 08/03/2004 11:56 PM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 04/13/2006 10:09 AM 49152 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 01/19/2007 11:54 AM 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 07/09/2001 12:50 AM 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 10/20/2008 10:02 AM 98304 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 12/07/2005 09:57 PM 30208 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 07/26/2006 02:03 AM 49263 C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 10/20/2008 10:00 AM 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 10/24/2006 03:10 PM 4662776 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\S3Trayp]
--a------ 07/11/2006 01:33 AM 176128 C:\WINDOWS\system32\S3Trayp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
--a------ 08/03/2006 01:53 PM 53248 C:\WINDOWS\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [12/13/2007 12:28 PM 24592]
R3 S3GIGP;S3GIGP;C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [09/12/2006 09:43 AM 659456]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{55ea83d0-9ede-11dd-824b-00140b304851}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{55ea83d1-9ede-11dd-824b-00140b304851}]
\Shell\AutoRun\command - G:\System\DriveGuard\DriveProtect.exe -run
\Shell\Explore\Command - G:\System\DriveGuard\DriveProtect.exe -run
\Shell\Open\Command - G:\System\DriveGuard\DriveProtect.exe -run
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-10-30 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE []
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 -: Microsoft XML Parser for Java -
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
.
------- File Associations -------
.
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-30 02:08:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 10/30/2008 2:09:43
ComboFix-quarantined-files.txt 2008-10-30 10:09:38
ComboFix2.txt 2008-10-30 10:00:39
Pre-Run: 35,342,295,040 bytes free
Post-Run: 35,333,410,816 bytes free
184