تقرير ComboFix
ComboFix 08-10-30.12 - qatar 10/31/2008 21:05:24.4 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1256.1.1033.18.1405 [GMT 3:00]
Running from: C:\Users\qatar\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Program Files\Zumie
.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-31 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-31 18:04 352,288 --sha-w C:\Windows\system32\drivers\fidbox2.dat
2008-10-31 18:03 --------- d-----w C:\ProgramData\Kaspersky Lab
2008-10-31 18:01 31,500 --sha-w C:\Windows\system32\drivers\fidbox.idx
2008-10-31 18:01 3,759,648 --sha-w C:\Windows\system32\drivers\fidbox.dat
2008-10-31 18:01 2,256 --sha-w C:\Windows\system32\drivers\fidbox2.idx
2008-10-31 13:42 --------- d-----w C:\ProgramData\Avira
2008-10-31 13:42 --------- d-----w C:\Program Files\Avira
2008-10-31 09:57 --------- d-----w C:\Program Files\CCleaner
2008-10-31 08:45 --------- d-----w C:\Program Files\Alwil Software
2008-10-30 22:17 --------- d-----w C:\Program Files\Wise Registry Cleaner 3
2008-10-30 22:17 --------- d-----w C:\Program Files\Wise Disk Cleaner 3 Pro
2008-10-30 22:16 --------- d-----w C:\ProgramData\SymplisIT
2008-10-30 22:16 --------- d-----w C:\ProgramData\Roxio
2008-10-30 22:02 --------- d-----w C:\Users\qatar\AppData\Roaming\CyberScrub
2008-10-30 22:02 --------- d-----w C:\Users\qatar\AppData\Roaming\cleaner
2008-10-30 20:43 --------- d---a-w C:\ProgramData\TEMP
2008-10-30 16:58 --------- d-----w C:\ProgramData\Messenger Plus!
2008-10-30 03:06 96,976 ----a-w C:\Windows\system32\drivers\klin.dat
2008-10-30 03:04 --------- d-----w C:\Program Files\Common Files\delet
2008-10-30 02:45 87,855 ----a-w C:\Windows\system32\drivers\klick.dat
2008-10-30 02:44 --------- d-----w C:\Program Files\Kaspersky Lab
2008-10-29 16:03 --------- d-----w C:\Program Files\RogueRemover PRO
2008-10-29 15:39 --------- d-----w C:\Program Files\Advanced PC Tweaker
2008-10-29 02:07 --------- d-----w C:\Program Files\Windows Mail
2008-10-28 16:33 --------- d-----w C:\Program Files\Uniblue
2008-10-28 16:20 --------- d-----w C:\ProgramData\DriverScanner
2008-10-28 16:12 --------- d-----w C:\Program Files\HP
2008-10-07 10:12 --------- d--h--w C:\ProgramData\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2008-10-06 22:30 --------- d-----w C:\Program Files\BearShare Applications
2008-10-06 21:23 --------- d-----w C:\Users\qatar\AppData\Roaming\Thinstall
2008-10-06 21:12 --------- d-----w C:\Users\qatar\AppData\Roaming\Business Logic
2008-10-06 21:12 --------- d-----w C:\Program Files\BearShareGoldDownloader
2008-10-06 19:05 --------- d-----w C:\Users\qatar\AppData\Roaming\BearShare
2008-10-06 04:26 27,335 ----a-w C:\Users\qatar\AppData\Roaming\nvModes.dat
2008-10-06 03:38 --------- d-----w C:\Program Files\SymplisIT
2008-10-06 03:16 --------- d-----w C:\Program Files\XPC Tools
2008-10-06 02:13 --------- d-----w C:\ProgramData\ma-config.com
2008-10-06 02:13 --------- d-----w C:\Program Files\ma-config.com
2008-10-06 01:49 --------- d-----w C:\Users\qatar\AppData\Roaming\Uniblue
2008-10-06 01:36 --------- d-----w C:\Program Files\Intel
2008-10-06 01:25 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-06 01:25 --------- d-----w C:\Users\qatar\AppData\Roaming\InstallShield
2008-10-06 01:25 --------- d-----w C:\Program Files\Realtek
2008-10-06 00:12 --------- d-----w C:\Program Files\Driver-Soft
2008-10-05 23:48 --------- d-----w C:\ProgramData\PC Drivers Headquarters
2008-10-05 18:06 --------- d-----w C:\Program Files\Java
2008-10-05 01:11 --------- d-----w C:\Users\qatar\AppData\Roaming\URSoft
2008-10-05 00:59 --------- d-----w C:\Program Files\a-squared Anti-Malware
2008-10-04 23:14 --------- d-----w C:\Program Files\IObit
2008-10-04 06:08 --------- d-----w C:\Users\qatar\AppData\Roaming\GlarySoft
2008-10-04 05:27 --------- d-----w C:\Program Files\Paltalk Messenger
2008-10-03 23:18 --------- d-----w C:\Program Files\Windows Live
2008-10-03 23:18 --------- d-----w C:\Program Files\MSN Messenger
2008-10-03 23:18 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-10-02 03:49 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-10-02 03:49 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-10-02 03:49 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-10-02 03:48 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-09-30 01:10 --------- d-----w C:\ProgramData\Kaspersky Lab Setup Files
2008-09-30 01:08 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-30 01:02 --------- d-----w C:\Program Files\Common Files\Borland Shared
2008-09-29 02:01 268,800 ----a-w C:\Windows\System32\es.dll
2008-09-28 03:28 174 --sha-w C:\Program Files\desktop.ini
2008-09-28 03:21 --------- d-----w C:\Program Files\Windows Defender
2008-09-28 03:21 --------- d-----w C:\Program Files\Windows Calendar
2008-09-28 03:20 --------- d-----w C:\Program Files\Windows Sidebar
2008-09-28 02:32 61,440 ----a-w C:\Windows\System32\winipsec.dll
2008-09-28 02:32 361,984 ----a-w C:\Windows\System32\IPSECSVC.DLL
2008-09-28 02:32 28,672 ----a-w C:\Windows\System32\FwRemoteSvr.dll
2008-09-28 02:32 272,896 ----a-w C:\Windows\System32\polstore.dll
2008-09-28 02:30 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-09-28 02:30 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-09-28 02:30 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-09-28 02:30 28,160 ----a-w C:\Windows\System32\Apphlpdm.dll
2008-09-28 02:30 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-09-28 02:30 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-09-28 02:30 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-09-28 02:30 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-09-28 02:29 87,040 ----a-w C:\Windows\System32\msoert2.dll
2008-09-28 02:29 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
2008-09-28 02:29 205,824 ----a-w C:\Windows\System32\msoeacct.dll
2008-09-28 02:27 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-09-28 02:27 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-09-28 02:26 49,664 ----a-w C:\Windows\System32\csrsrv.dll
2008-09-28 02:26 376,320 ----a-w C:\Windows\System32\winsrv.dll
2008-09-28 02:22 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys
2008-09-28 02:22 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-09-28 02:22 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-09-28 02:21 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
2008-09-28 02:20 414,208 ----a-w C:\Windows\System32\msscp.dll
2008-09-28 02:20 303,616 ----a-w C:\Windows\System32\wmpeffects.dll
2008-09-28 02:19 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2008-09-28 02:19 7,680 ----a-w C:\Windows\System32\spwmp.dll
2008-09-28 02:19 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2008-09-28 02:19 356,864 ----a-w C:\Windows\System32\MediadataHandler.dll
2008-09-28 02:18 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2008-09-28 02:18 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-09-28 02:18 61,952 ----a-w C:\Windows\System32\cmifw.dll
2008-09-28 02:18 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2008-09-28 02:18 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [01/19/2007 10:54 PM 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [07/29/2008 08:20 PM 206088]
"MSConfig"="C:\Windows\system32\msconfig.exe" [11/02/2006 12:45 PM 222208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.speex32"= speex32.acm
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\Windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=C:\Windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^qatar^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Users\qatar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\Windows\pss\Adobe Reader Speed Launch.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
--a------ 06/12/2008 02:28 PM 266497 C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
--a------ 03/12/2007 09:54 PM 50696 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 05/08/2007 04:24 PM 54840 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
--a------ 03/01/2007 11:18 PM 472776 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 05/01/2007 01:27 PM 8429568 C:\WINDOWS\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 05/01/2007 01:27 PM 81920 C:\WINDOWS\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 05/01/2007 01:27 PM 86016 C:\WINDOWS\System32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 06/10/2008 04:27 AM 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
--a------ 01/11/2007 02:12 AM 317128 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 09/09/2008 08:32 PM 6281760 C:\WINDOWS\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{406F03BD-EFA3-4B9D-8B25-2A903A5FC6A7}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{162B159F-C65A-4FC2-B781-EE593350C13A}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
"{C2DD4FDE-A09E-4A8E-AD94-388E40E91911}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{F4B7CBBD-699C-4D14-85DB-A9649DBB37C4}"= UDP:C:\Users\qatar\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
"{9EDBFBD1-7346-49EE-BAED-6E5AE256ACE3}"= TCP:C:\Users\qatar\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\Windows\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [07/19/2008 05:35 PM 78416]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [07/09/2008 06:28 PM 20496]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [07/19/2008 05:37 PM 20560]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [07/19/2008 05:36 PM 51280]
R3 btwaudio;Bluetooth Audio Device Service;C:\Windows\system32\drivers\btwaudio.sys [01/02/2007 01:45 PM 78128]
R3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [01/02/2007 01:45 PM 80688]
R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [01/02/2007 01:45 PM 16560]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\Windows\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw5v32.sys [06/26/2008 08:30 AM 3662848]
S3 tapvpn;TAP VPN Adapter;C:\Windows\system32\DRIVERS\tapvpn.sys [01/24/2008 12:25 AM 27136]
S4 AntiVirMailService;Avira AntiVir Premium MailGuard;C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe [07/11/2008 12:23 PM 164097]
S4 antivirwebservice;Avira AntiVir Premium WebGuard;C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE [06/12/2008 02:59 PM 258305]
S4 AVEService;Avira AntiVir Premium MailGuard helper service;C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe [05/09/2008 01:22 PM 41217]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
R0 -: HKLM-Main,Start Page = about:blank
O8 -: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 -: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-31 21:11:08
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 10/31/2008 21:12:23
ComboFix-quarantined-files.txt 2008-10-31 18:12:19
Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application.
Post-Run: 112,544,157,696 bytes free
226 --- E O F --- 2008-10-30 01:12:32