ComboFix 08-11-28.02 - Administrator 11/28/2008 23:04:22.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.529 [GMT 1:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-28 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-28 22:08 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-28 22:06 385,056 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-28 22:06 2,396 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-28 22:06 15,752 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-28 22:06 1,878,048 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-28 20:30 --------- d-----w c:\documents and settings\Administrator\Application Data\skypePM
2008-11-28 20:30 --------- d-----w c:\documents and settings\Administrator\Application Data\Skype
2008-11-27 16:50 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-25 06:57 --------- d-----w c:\program files\SUPERAntiSpyware
2008-11-23 14:23 --------- d-----w c:\program files\Common Files\Skype
2008-11-23 14:23 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-11-23 14:23 --------- d-----r c:\program files\Skype
2008-11-23 12:10 --------- d-----w c:\program files\Windows Live
2008-11-23 12:09 --------- d-----w c:\program files\Adobe Photoshop CS
2008-11-21 22:14 --------- d-----w c:\program files\DrWeb
2008-11-21 17:33 --------- d-----w c:\program files\Ashampoo
2008-11-21 16:39 --------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-11-21 16:39 --------- d-----w c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-11-21 16:38 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-21 14:39 --------- d-----w c:\program files\Alwil Software
2008-11-21 12:20 96,976 ----a-w c:\windows\system32\drivers\klin.dat
2008-11-21 12:11 87,855 ----a-w c:\windows\system32\drivers\klick.dat
2008-11-21 12:11 --------- d-----w c:\program files\Kaspersky Lab
2008-11-21 12:01 --------- d-----w c:\documents and settings\All Users\Application Data\Avg8
2008-11-21 08:00 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-11-21 07:21 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-18 09:49 --------- d-----w c:\program files\Microsoft
2008-11-18 09:36 --------- d-----w c:\program files\Common Files\Windows Live
2008-11-18 08:41 --------- d-----w c:\program files\ImTOO
2008-11-17 08:14 --------- d-----w c:\program files\WinASO
2008-11-11 16:55 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-11 07:54 --------- dc-h--w c:\documents and settings\All Users\Application Data\{8CC5CF4A-124E-41BA-B58C-A41F05BE09CC}
2008-11-11 07:51 --------- d-----w c:\documents and settings\Administrator\Application Data\OtakuSoftware
2008-11-11 07:49 63,281 ----a-w c:\windows\BricoPackUninst.cmd
2008-11-11 07:49 6,112 ----a-w c:\windows\BricoPackFoldersDelete.cmd
2008-11-11 07:38 --------- d-----w c:\program files\RocketDock
2008-11-11 07:32 --------- d-----w c:\program files\ENT
2008-11-11 07:21 --------- d-----w c:\program files\Stardock
2008-11-11 06:22 --------- d--h--w c:\documents and settings\Administrator\Application Data\IFBuilder
2008-11-10 20:08 --------- d-----w c:\documents and settings\Administrator\Application Data\Thinstall
2008-11-10 11:36 --------- d-----w c:\program files\Real
2008-11-10 11:36 --------- d-----w c:\program files\Common Files\xing shared
2008-11-10 11:36 --------- d-----w c:\program files\Common Files\Real
2008-11-09 16:39 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-09 13:49 --------- d-----w c:\program files\microsoft frontpage
2008-11-09 13:09 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-09 12:31 --------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2008-11-09 12:29 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2008-11-09 11:32 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-11-09 11:29 --------- d-----w c:\program files\Yahoo!
2008-11-09 10:44 --------- d-----w c:\documents and settings\Administrator\Application Data\AvaFind Data
2008-11-09 09:20 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-09 09:20 --------- d-----w c:\program files\Realtek
2008-11-09 09:07 --------- d-----w c:\program files\Total Video Converter
2008-11-09 09:07 --------- d-----w c:\program files\Internet Download Manager
2008-11-09 09:07 --------- d-----w c:\program files\ImageShack
2008-11-09 09:07 --------- d-----w c:\program files\AVI MPEG RM WMV Splitter
2008-11-09 09:07 --------- d-----w c:\program files\AVI MPEG RM WMV Joiner
2008-11-09 09:07 --------- d-----w c:\program files\Avant Browser
2008-11-09 09:06 --------- d-----w c:\program files\Windows Media Connect 2
2008-10-31 02:28 551,179 ----a-w C:\Vista Pink.exe
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-09-05 15:04 287,744 ----a-w c:\windows\WLXPGSS.SCR
.
------- Sigcheck -------
06/23/2008 04:38 PM 827904 bd4be2824bc805da1f29385519b865f9 c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
08/20/2008 06:33 AM 666112 89ac84e7222d5ec0aca3cd88188cff5f c:\windows\$hf_mig$\KB956390\SP2QFE\wininet.dll
08/20/2008 06:10 AM 664576 b67627f9fe98061a23d0ae3f16cd7c9b c:\windows\$hf_mig$\KB956390\SP3GDR\wininet.dll
08/20/2008 06:06 AM 665088 02b59535250fd4f4a2d2ab005a35bae5 c:\windows\$hf_mig$\KB956390\SP3QFE\wininet.dll
08/26/2008 10:08 AM 827904 bceb6d8a6bea74628db977215081652a c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
04/07/2008 11:47 PM 689152 c738ab256d55a0ace7f4f4ce1a1c0f31 c:\windows\ie7\wininet.dll
08/13/2007 05:54 PM 818688 a4a0fc92358f39538a6494c42ef99fe9 c:\windows\ie7updates\KB953838-IE7\wininet.dll
06/23/2008 05:15 PM 826368 3f4bca25f29394995161e8e85d925c1a c:\windows\ie7updates\KB956390-IE7\wininet.dll
08/26/2008 08:57 AM 826368 8d2003bbfffd5ff95ea66350e4d1e4c7 c:\windows\ie8\wininet.dll
08/22/2008 02:08 AM 869376 f921f8c0bf1e6e83cba3227d8a86d06a c:\windows\ServicePackFiles\i386\wininet.dll
06/23/2008 05:15 PM 826368 3f4bca25f29394995161e8e85d925c1a c:\windows\SoftwareDistribution\Download\c8f51fe07131d22c00726ac1331d586c\SP2GDR\wininet.dll
06/23/2008 04:38 PM 827904 bd4be2824bc805da1f29385519b865f9 c:\windows\SoftwareDistribution\Download\c8f51fe07131d22c00726ac1331d586c\SP2QFE\wininet.dll
08/26/2008 08:57 AM 826368 8d2003bbfffd5ff95ea66350e4d1e4c7 c:\windows\SoftwareDistribution\Download\d40590bd9995150537adaa5ab5401235\SP2GDR\wininet.dll
08/26/2008 10:08 AM 827904 bceb6d8a6bea74628db977215081652a c:\windows\SoftwareDistribution\Download\d40590bd9995150537adaa5ab5401235\SP2QFE\wininet.dll
08/22/2008 02:08 AM 869376 f921f8c0bf1e6e83cba3227d8a86d06a c:\windows\system32\wininet.dll
08/22/2008 02:08 AM 878592 df1cb456ed1e038b276123365a1a93c4 c:\windows\system32\dllcache\wininet.dll
04/14/2008 04:59 PM 974848 5320ea6507cfa8abc92caf91cd2fc8a5 c:\windows\explorer.exe
04/17/2008 07:46 PM 1568256 701e4ac567cc8c64357da9e69fff62eb c:\windows\$NtServicePackUninstall$\explorer.exe
04/14/2008 04:59 PM 974848 5320ea6507cfa8abc92caf91cd2fc8a5 c:\windows\ServicePackFiles\i386\explorer.exe
10/16/2008 02:09 PM 66584 2275f45e257d46e6500558b2930cb9a4 c:\windows\ServicePackFiles\i386\wuauclt.exe
10/16/2008 02:09 PM 66584 2275f45e257d46e6500558b2930cb9a4 c:\windows\system32\wuauclt.exe
10/16/2008 02:09 PM 51224 e654b78d2f1d791b30d0ed9a8195ec22 c:\windows\system32\dllcache\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [04/14/2008 04:59 PM 15360]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [11/05/2008 09:59 PM 4347120]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [09/09/2008 12:02 AM 3513344]
"AnalogClock"="c:\program files\ENT\Analog Clock\AnalogClock.exe" [11/05/2005 12:10 PM 480256]
"TransBar"="c:\program files\ENT\TransBar\TransBar.exe" [06/01/2005 09:41 PM 81920]
"TopDesk"="c:\program files\ENT\TopDesk\topdesk.exe" [06/20/2007 02:21 PM 1912832]
"UberIcon"="c:\program files\ENT\UberIcon\UberIcon Manager.exe" [05/21/2006 09:43 AM 180224]
"Visual Task Tips"="c:\program files\ENT\VisualTaskTips\VisualTaskTips.exe" [09/05/2007 11:20 PM 36352]
"RocketDock"="c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [03/18/2007 11:05 PM 630784]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [10/29/2008 06:39 PM 25798440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DrvIcon"="c:\windows\VistaDrives\DrvIcon.exe" [07/04/2007 08:59 PM 45056]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [08/16/2006 08:35 AM 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [08/16/2006 08:35 AM 86016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [11/10/2008 12:36 PM 185872]
"KRun"="c:\program files\ENT\RunMe\RunMe.exe" [04/06/2007 08:15 PM 518656]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [07/29/2008 08:20 PM 206088]
"Ashampoo AntiSpyWare 2 Guard"="c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWare2Guard.exe" [11/04/2008 02:32 PM 2347352]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [11/18/2008 06:39 PM 81000]
"nwiz"="nwiz.exe" [08/16/2006 08:35 AM 1617920 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [12/19/2006 04:12 AM 16062464 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [05/16/2006 11:04 AM 2879488 c:\windows\SkyTel.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"WIAWizardMenu"="c:\windows\system32\sti_ci.dll" [04/14/2008 04:59 PM 136192]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 04:59 PM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [08/22/2008 02:06 AM 128512 c:\windows\system32\advpack.dll]
c:\documents and settings\Administrator\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]
YzShadow.lnk - c:\program files\ENT\YzShadow\YzShadow.exe [2008-11-11 155648]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [05/13/2008 10:13 AM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
07/23/2008 04:28 PM 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
01/14/2008 06:04 AM 210168 c:\program files\Stardock\ Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-24 78416]
R2 AASW2_Service;Ashampoo AntiSpyWare 2 Service;c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWareService.exe [2008-11-21 749400]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-24 20560]
R2 fssfltr;FssFltr;c:\windows\system32\DRIVERS\fssfltr.sys [2008-11-18 56344]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
S3 fsssvc;Windows Live Family Safety;"c:\program files\Windows Live\Family Safety\fsssvc.exe" [2008-09-04 512536]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\E:\NTGLM7X.sys []
*Newly Created Service* - HELPSVC
.
s of the 'Scheduled Tasks' folder
2008-11-28 c:\windows\Tasks\User_Feed_Synchronization-{0F8B6DCE-639E-4851-A9FC-2F4D7371EB32}.job
- c:\windows\system32\msfeedssync.exe [08/22/2008 02:05 AM]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-28 23:08:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(992)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\program files\Stardock\ Desktop\WindowBlinds\wbsrv.dll
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
- - - - - - - > 'lsass.exe'(1048)
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
- - - - - - - > 'explorer.exe'(2416)
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
c:\program files\ENT\YzShadow\YzShadow.dll
c:\program files\ENT\TopDesk\topdesk153.dll
c:\program files\ENT\VisualTaskTips\VttHooks.dll
c:\program files\ENT\UberIcon\UberIcon.dll
- - - - - - - > 'csrss.exe'(968)
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 11/28/2008 23:11:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-28 22:11:38
Pre-Run: 144,554,549,248 bytes free
Post-Run: 145,957,888,000 bytes free
219 --- E O F --- 2008-11-12 06:38:00