ComboFix 08-11-02.05 - باقيس 11/05/2008 15:35:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.54 [GMT 3:00]
Running from: c:\documents and settings\باقيس\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-10-05 to 2008-11-05 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-05 12:28 --------- d-----w c:\program files\Kaspersky Lab
2008-11-05 12:25 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-05 11:30 73,760 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-05 11:22 2,352 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-05 11:19 1,360 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-05 11:18 32,736 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-03 19:20 --------- d-----w c:\documents and settings\All Users\Application Data\zyz Kaspersky Lab setup files
2008-11-03 13:59 --------- d-----w c:\documents and settings\باقيس\Application Data\Media Player Classic
2008-11-03 13:59 --------- d-----w c:\documents and settings\باقيس\Application Data\Media Player Classic
2008-11-03 13:59 --------- d-----w c:\documents and settings\باقيس\Application Data\Media Player Classic
2008-11-03 13:18 --------- d-----w c:\program files\Windows Live
2008-11-03 13:15 --------- d-----w c:\program files\Java
2008-11-03 13:11 --------- d-----w c:\program files\Common Files\Java
2008-11-03 12:56 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-03 12:38 --------- d-----w c:\program files\Windows Media Connect 2
2008-11-03 12:23 --------- d-----w c:\program files\Foxit Software
2008-11-03 12:18 --------- d-----w c:\program files\Microsoft.NET
2008-11-03 12:02 --------- d-----w c:\program files\Common Files\bronz
2008-11-03 11:02 --------- d-----w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_04\bin\jusched.exe" [12/14/2007 03:42 AM 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R3 SiSV6306;SiSV6306;c:\windows\system32\DRIVERS\SiS6306p.sys [08/17/2001 03:50 PM 68608]
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
O8 -: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-05 15:47:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/05/2008 15:52:12
ComboFix-quarantined-files.txt 2008-11-05 12:51:45
Pre-Run: 12,983,066,624 bytes free
Post-Run: 12,977,213,440 bytes free
76