ComboFix 08-11-26.03 - user 11/26/2008 8:40:21.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.696 [GMT 3:00]
Running from: c:\documents and settings\user\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\FunWebProducts
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\bar\Settings\setting2.htm
c:\program files\MyWebSearch\bar\Settings\settings.dat
.
((((((((((((((((((((((((( Files Created from 2008-10-26 to 2008-11-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-26 05:43 32 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-26 05:43 32 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-26 05:43 32 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-26 05:43 32 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-19 23:05 --------- d-----w c:\program files\JavaSoft
2008-11-11 06:46 --------- d-----w c:\program files\PhotoArtMaster Limited Use Download Edition
2008-11-10 09:15 96,976 ----a-w c:\windows\system32\drivers\klin.dat
2008-11-10 07:14 87,855 ----a-w c:\windows\system32\drivers\klick.dat
2008-11-10 07:06 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-23 02:05 --------- d-----w c:\documents and settings\LocalService\Application Data\agi
2008-10-23 01:53 339,968 ----a-w c:\windows\system32\pythoncom25.dll
2008-10-23 01:53 2,117,632 ----a-w c:\windows\system32\python25.dll
2008-10-23 01:53 114,688 ----a-w c:\windows\system32\pywintypes25.dll
2008-10-19 11:38 --------- d-----w c:\documents and settings\All Users\Application Data\IM
2008-10-19 11:34 --------- d-----w c:\program files\IncrediMail
2008-10-19 11:34 --------- d-----w c:\documents and settings\All Users\Application Data\IncrediMail
2008-09-16 16:26 1,332,197 ----a-w c:\windows\system32\pythondll.zip
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:00 PM 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [07/10/2008 03:02 PM 171448]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [08/04/2004 01:09 AM 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AsusTray"="c:\program files\Asus\EeePC ACPI\AsTray.exe" [03/20/2008 09:04 PM 102400]
"AsusACPIServer"="c:\program files\Asus\EeePC ACPI\AsAcpiSvr.exe" [03/20/2008 12:52 PM 544768]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [10/08/2006 08:11 AM 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [10/08/2006 08:13 AM 114688]
"Persistence"="c:\windows\system32\igfxpers.exe" [10/08/2006 08:10 AM 94208]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [03/24/2008 03:03 PM 339968]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM 31016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [07/20/2008 12:14 AM 185896]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [07/29/2008 08:20 PM 206088]
"RTHDCPL"="RTHDCPL.EXE" [03/06/2008 12:14 PM 16858112 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:00 PM 15360]
c:\documents and settings\user\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\BINARIES\\HelpCtr.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\DRIVERS\ASUSACPI.sys [2008-06-30 11264]
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;c:\windows\system32\DRIVERS\l251x86.sys [2008-06-30 30720]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
R3 Ktp;Elantech Smart-Pad;c:\windows\system32\DRIVERS\ETD.sys [2008-06-30 24064]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34d592e0-8cee-11dd-b5cc-0015afa68f9c}]
\Shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c0d8540-8f90-11dd-b5d5-0015afa68f9c}]
\Shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94c1fe0e-469f-11dd-b56e-0015afa68f9c}]
\Shell\AutoRun\command - G:\t.com
\Shell\explore\Command - G:\t.com
\Shell\open\Command - G:\t.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94c1fe0f-469f-11dd-b56e-0015afa68f9c}]
\Shell\AutoRun\command - H:\t.com
\Shell\explore\Command - H:\t.com
\Shell\open\Command - H:\t.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd714f58-8cef-11dd-b5cd-0015afa68f9c}]
\Shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9dc4574-4762-11dd-b575-0015afa68f9c}]
\Shell\AutoRun\command - E:\AutoRun.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-IncrediMail - c:\program files\IncrediMail\bin\IncMail.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.alarabiya.net/default.html
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
c:\windows\Downloaded Program Files\InstallerControl.dll - O16 -: CabBuilder
hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
c:\windows\Downloaded Program Files\OSDC5.OSD
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-26 08:44:58
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\IGFXSRVC.EXE
c:\windows\SYSTEM32\IGFXEXT.EXE
.
**************************************************************************
.
Completion time: 11/26/2008 8:49:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-26 05:49:30
Pre-Run: 9,437,437,952 bytes free
Post-Run: 9,602,818,048 bytes fre