ComboFix 08-12-14.03 - hcc 12/15/2008 2:26:55.4 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.502.227 [GMT 3:00]
Running from: c:\documents and settings\hcc\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\agsaame.dll
c:\windows\system32\ALOAudioFile2.dll
c:\windows\system32\ALOAVIFile.dll
c:\windows\system32\ALOQuickTimeFile.dll
c:\windows\system32\ALOVideoCoreM.dll
c:\windows\system32\ALOWMAFile2.dll
c:\windows\system32\kakle.dll
c:\windows\system32\tmp.reg
c:\windows\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-11-14 to 2008-12-14 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-14 19:03 57,376 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-12-14 19:03 3,124 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-14 19:03 261,664 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-14 19:03 1,276 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-12-04 21:57 778,240 ----a-w c:\windows\system32\ALOAudioCompress2.dll
2008-12-04 21:57 2,846,720 ----a-w c:\windows\system32\ALOAudioCompress3.dll
2008-12-02 17:48 --------- d-----w c:\documents and settings\hcc\Application Data\Media Player Classic
2008-12-02 17:47 --------- d-----w c:\program files\Media Player Classic
2008-12-02 17:46 --------- d-----w c:\program files\Real Alternative
2008-12-01 17:46 139,264 ----a-w c:\windows\system32\unzip.exe
2008-12-01 17:45 --------- d-----w c:\program files\ALBATTAR
2008-11-30 08:48 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2008-11-30 08:07 --------- d-----w c:\program files\PConPoint
2008-11-27 09:35 --------- d-----w c:\program files\vanBasco's Karaoke Player
2008-11-27 09:31 --------- d-----w c:\program files\DSL Speed
2008-11-25 17:21 --------- d-----w c:\documents and settings\hcc\Application Data\Xilisoft Corporation
2008-11-17 00:46 --------- d-----w c:\program files\Moodysoft
2008-11-13 19:05 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2008-11-13 00:24 --------- d-----w c:\documents and settings\All Users\Application Data\Winferno
2008-11-12 17:58 --------- d-----w c:\program files\XP TCPIP Repair
2008-11-09 17:42 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-11-09 17:42 --------- d-----w c:\program files\Common Files\xing shared
2008-11-09 16:44 98,304 ----a-w c:\windows\system32\viscomtran.dll
2008-11-09 16:44 86,016 ----a-w c:\windows\system32\viscomframe.dll
2008-11-09 16:44 81,920 ----a-w c:\windows\system32\viscomwave.dll
2008-11-09 16:44 602,112 ----a-w c:\windows\system32\viscomqtde.dll
2008-11-09 16:44 48,640 ----a-w c:\windows\system32\viscomsamplerate.dll
2008-11-09 16:44 147,456 ----a-w c:\windows\system32\viscomqtenc.dll
2008-11-09 16:44 118,784 ----a-w c:\windows\system32\viscomrmenc.dll
2008-11-09 16:44 118,784 ----a-w c:\windows\system32\viscomflvdec.dll
2008-11-09 16:44 1,470,464 ----a-w c:\windows\system32\viscomm4aenc.dll
2008-11-09 16:44 1,470,464 ----a-w c:\windows\system32\viscomdata3.dll
2008-11-09 16:44 1,462,272 ----a-w c:\windows\system32\viscomflvenc.dll
2008-11-09 16:44 1,454,080 ----a-w c:\windows\system32\viscomdata2.dll
2008-11-08 18:39 --------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2008-11-02 18:14 --------- d-sh--w c:\program files\Common Files\WindowsLiveInstaller
2008-11-02 18:13 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-10-28 11:50 57,344 ----a-w c:\windows\system32\IMSInfo.dll
2008-10-28 11:50 397,312 ----a-w c:\windows\system32\imcv1.dll
2008-10-26 17:02 --------- d-----w c:\documents and settings\hcc\Application Data\TeamViewer
2008-10-25 21:40 --------- d-----w c:\program files\KLC
2008-10-25 21:36 --------- d-----w c:\program files\Godlike Developers
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:21 455,296 ------w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 21:20 --------- d-----w c:\program files\MSN Messenger
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 12:36 286,720 ------w c:\windows\system32\dllcache\gdi32.dll
2008-10-22 16:50 --------- d-----w c:\documents and settings\hcc\Application Data\CyberScrub
2008-10-22 16:49 --------- d-----w c:\documents and settings\hcc\Application Data\cleaner
2008-10-21 18:42 --------- d-----w c:\program files\CCleaner
2008-10-16 19:28 --------- d-----w c:\documents and settings\All Users\Application Data\Grid Blue Memo Site
2008-10-16 11:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 11:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 11:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 11:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 11:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 11:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 11:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 11:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 11:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 11:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 11:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 11:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 11:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 11:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 11:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 11:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 11:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 01:00 664,576 ----a-w c:\windows\system32\wininet.dll
2008-10-16 01:00 664,576 ------w c:\windows\system32\dllcache\wininet.dll
2008-10-16 01:00 617,472 ------w c:\windows\system32\dllcache\urlmon.dll
2008-10-16 01:00 3,088,896 ------w c:\windows\system32\dllcache\mshtml.dll
2008-10-16 01:00 1,499,136 ------w c:\windows\system32\dllcache\shdocvw.dll
2008-10-15 16:35 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-06 16:09 344,064 ----a-w c:\windows\system32\dkll.dll
2008-10-06 16:09 196,608 ----a-w c:\windows\system32\maag.dll
2008-10-06 16:09 1,986,560 ----a-w c:\windows\system32\akll.dll
2008-10-06 16:09 1,212,416 ----a-w c:\windows\system32\ckll.dll
2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-10-03 10:03 247,326 ----a-w c:\windows\system32\dllcache\strmdll.dll
2008-09-30 13:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-24 17:41 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-09-24 17:35 155,995 ----a-w c:\windows\java\Packages\PF1NDBVX.ZIP
2008-09-24 17:34 73,216 ----a-w c:\windows\ST6UNST.EXE
2008-09-24 17:34 47,104 ------w c:\windows\AKDeInstall.exe
2008-09-24 17:34 172,032 ------w c:\windows\Setup1.exe
2008-09-24 17:32 402,226 ----a-w c:\windows\system32\cdky1.reg
2008-09-15 15:24 1,846,272 ----a-w c:\windows\system32\win32k.sys
2008-09-15 15:24 1,846,272 ------w c:\windows\system32\dllcache\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
11/14/2008 07:09 AM 200192 --a------ c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [04/14/2008 09:29 PM 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [12/02/2004 06:23 PM 102400]
"AFProg"="c:\program files\Hotspot Shield\AnchorFree\ctrl\AFController.exe" [06/26/2006 05:26 AM 118784]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [09/15/2008 09:30 PM 2606512]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [04/14/2008 09:30 PM 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [12/11/2008 11:08 PM 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"snpstd"="c:\windows\vsnpstd.exe" [06/10/2004 01:48 PM 286720]
"UpdReg"="c:\windows\UpdReg.EXE" [05/11/2000 01:00 AM 90112]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [02/15/2005 04:10 PM 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM 144784]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [07/29/2008 08:20 PM 206088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [11/09/2008 08:42 PM 185872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [06/12/2008 11:38 AM 34672]
"BluetoothAuthenticationAgent"="bthprops.cpl" [04/14/2008 09:30 PM 110592 c:\windows\system32\bthprops.cpl]
"P17Helper"="P17.dll" [05/03/2005 06:38 AM 64512 c:\windows\system32\P17.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 09:29 PM 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-09-24 113664]
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2008-11-14 11376640]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChange"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
backup=c:\windows\pss\PalTalk.lnkCommon Startup
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalTalk.lnk
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
-ra------ 11/28/2005 08:52 AM 77824 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
-ra------ 11/28/2005 08:55 AM 118784 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
-ra------ 11/28/2005 08:55 AM 98304 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP

xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP

xpsp2res.dll,-22016
"500:UDP"= 500:UDP

xpsp2res.dll,-22017
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6887da6-a906-11dd-bc58-0013eff1498c}]
\Shell\AutoRun\command - 2fiji.com
\Shell\explore\Command - 2fiji.com
\Shell\open\Command - 2fiji.com
.
s of the 'Scheduled Tasks' folder
2008-11-27 c:\windows\Tasks\rpc.job
- c:\program files\Winferno\RegistryPowerCleaner\RegPowerClean.exe []
2008-12-14 c:\windows\Tasks\PCConfidential.job
- c:\program files\Winferno\PC Confidential\PCConfidential.exe []
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
O16 -: Microsoft XML Parser for Java - c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\system32\msvcrt.dll - c:\windows\system32\mfc42.dll
c:\windows\system32\olepro32.dll
c:\windows\Downloaded Program Files\imcv1.dll
O16 -: {6924091F-CD97-41E1-B1D4-D9079409D413}
hxxp://voicechat.8rb.com/IMSCP/talk.cab
c:\windows\Downloaded Program Files\talk.inf
FF - ProfilePath - c:\documents and settings\hcc\Application Data\Mozilla\Firefox\Profiles\dpte7moj.default\
FF - plugin: c:\program files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF - plugin: c:\program files\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-15 02:28:25
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 12/15/2008 2:28:58
ComboFix-quarantined-files.txt 2008-12-14 23:28:58
ComboFix4.txt 2008-10-22 19:03:18
ComboFix3.txt 2008-10-24 00:44:32
ComboFix2.txt 2008-11-02 19:56:54
Pre-Run: 4,365,713,408 bytes free
Post-Run: 4,389,683,200 bytes free
237 --- E O F --- 2008-12-12 02:30:23