Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.2037.1431 [GMT 3:00]
Running from: c:\documents and settings\SLC\Desktop\اداة.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
FW: Kaspersky Anti-Virus *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\windows\IE4 Error Log.txt
.
((((((((((((((((((((((((( Files Created from 2009-03-01 to 2009-04-01 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-01 14:35 499,744 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-01 14:35 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-01 14:33 5,401,120 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-01 14:33 45,372 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-01 14:33 3,808 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-01 14:31 --------- d-----w c:\documents and settings\All Users\Application Data\NOS
2009-04-01 14:00 --------- d-----w c:\program files\NOS
2009-03-27 20:18 --------- d-----w c:\program files\ArcSoft
2009-03-26 11:32 --------- d-----w c:\program files\Golden Al-Wafi Translator
2009-03-25 10:53 --------- d-----w c:\documents and settings\SLC\Application Data\Apple Computer
2009-03-25 10:51 --------- d-----w c:\program files\Safari
2009-03-25 10:51 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-25 10:50 --------- d-----w c:\program files\Bonjour
2009-03-25 10:50 --------- d-----w c:\program files\Apple Software Update
2009-03-25 10:50 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2009-02-27 13:35 --------- d-----w c:\documents and settings\SLC\Application Data\Wildfire
2009-02-10 11:59 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-03 21:36 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-03 21:36 101,287 ----a-w c:\windows\system32\drivers\klin.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 10:56 AM 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [08/04/2004 01:06 AM 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m‘|\ü" [X]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [03/09/2005 03:39 PM 98304]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageWorkstation\TrueImageMonitor.exe" [03/09/2005 03:39 PM 785048]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [09/05/2007 12:13 PM 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [09/05/2007 12:13 PM 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [09/05/2007 12:13 PM 137752]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [11/25/2007 04:28 PM 185896]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [11/22/2006 12:31 PM 630784]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [02/12/2004 01:38 PM 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [05/12/2004 03:18 PM 241664]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [02/10/2009 02:59 PM 206088]
"pdfFactory Dispatcher v1"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis1.exe" [10/30/2002 04:59 PM 364544]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [05/10/2007 10:46 PM 624248]
"Adobe_ID0EYTHM"="c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [03/20/2007 04:40 PM 1884160]
"RTHDCPL"="RTHDCPL.EXE" [02/13/2008 09:31 AM 16857600 c:\windows\RTHDCPL.exe]
"Tweak UI"="TWEAKUI.CPL" [11/24/1998 11:02 AM 159744 c:\windows\system32\TWEAKUI.CPL]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 10:56 AM 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 53248]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 02/07/2007 04:21 PM 54832 c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 03/01/2007 03:57 PM 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 02/07/2007 04:24 PM 71216 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 09/25/2007 01:11 AM 132496 c:\program files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 11/25/2007 04:28 PM 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 03/03/2001 05:26 AM 7680 c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Common Files\\Acronis\\Agent\\agent.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\
000.fcl [2006-11-02 16:51:58 13560]
R2 AcronisAgent;Acronis Remote Agent;c:\program files\Common Files\Acronis\Agent\agent.exe [2005-03-09 59392]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{08f1c5c9-ba15-11dd-96c2-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL tazebama.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{404a1a05-ba18-11dd-a8b6-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL tazebama.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4b6039a2-ba02-11dd-8dbf-806d6172696f}]
\Shell\AutoRun\command - E:\
0hct8ybw.bat
\Shell\explore\Command - E:\
0hct8ybw.bat
\Shell\open\Command - E:\
0hct8ybw.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{633cd49c-b45b-11dd-9f53-806d6172696f}]
\Shell\AutoRun\command - E:\h1dwg20.exe
\Shell\explore\Command - E:\h1dwg20.exe
\Shell\open\Command - E:\h1dwg20.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{633cd49d-b45b-11dd-9f53-806d6172696f}]
\Shell\AutoRun\command - F:\h1dwg20.exe
\Shell\explore\Command - F:\h1dwg20.exe
\Shell\open\Command - F:\h1dwg20.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{74b53adc-b421-11dd-bcd1-001d7dc43893}]
\Shell\AUtOPLaY\CommAnd - E:\msffay.pif
\Shell\AutoRun\command - E:\msffay.pif
\Shell\eXploRe\COmmAnd - E:\msffay.pif
\Shell\opeN\CommaNd - E:\msffay.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77859d2a-a601-11dd-ab76-806d6172696f}]
\Shell\AutoRun\command - E:\bpu.exe
\Shell\explore\Command - E:\bpu.exe
\Shell\open\Command - E:\bpu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77859d2b-a601-11dd-ab76-806d6172696f}]
\Shell\AutoRun\command - F:\bpu.exe
\Shell\explore\Command - F:\bpu.exe
\Shell\open\Command - F:\bpu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77859d2c-a601-11dd-ab76-806d6172696f}]
\Shell\AutoRun\command - G:\bpu.exe
\Shell\explore\Command - G:\bpu.exe
\Shell\open\Command - G:\bpu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5fa235e-b99a-11dd-ae55-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL tazebama.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5fa235f-b99a-11dd-ae55-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL tazebama.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6705781-bafe-11dd-ba63-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL tazebama.exe
.
Contents of the 'Scheduled Tasks' folder
2009-03-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [07/30/2008 12:34 PM]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: الدليل السريع - c:\windows\ww80.html
IE: {{46012075-ED62-464b-9554-AD0BEC35D1EC} -
IE: {{46012076-ED62-464b-9554-AD0BEC35D1EC}
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-01 17:35:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\
000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1092)
c:\windows\system32\relog_ap.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\spool\drivers\w32x86\3\hpzeng10.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\windows\system32\wscntfy.exe
C:\
.
**************************************************************************
.
Completion time: 04/01/2009 17:38:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-01 14:38:43
Pre-Run: 82,787,860,480 bytes free
Post-Run: 82,864,738,304 bytes free
207