ComboFix 09-04-04.01 - amer 04/11/2009 22:26:25.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.1023.727 [GMT 3:00]
Running from: c:\documents and settings\amer\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\amer\Application Data\tazebama
c:\documents and settings\amer\Application Data\tazebama\tazebama.log
c:\windows\system32\404Fix.exe
c:\windows\system32\adfceecfaba_x.dll
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\pthreadGC2.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\Ultra.dll
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2009-03-11 to 2009-04-11 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-11 19:28 4,856 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-11 19:28 215,072 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-11 19:28 2,184 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-11 19:28 16,416 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-10 13:02 --------- d-----w c:\program files\K-Lite Codec Pack
2009-04-10 12:20 --------- d-----w c:\program files\SpywareBlaster
2009-04-09 09:21 --------- d-----w c:\program files\WallCal
2009-04-09 07:09 --------- d-----w c:\documents and settings\amer\Application Data\TypingMaster7
2009-04-09 07:08 --------- d-----r c:\program files\TypingMaster
2009-04-09 06:48 2,560 ----a-w c:\windows\system32\drivers\mchInjDrv.sys
2009-04-02 12:21 84,480 ----a-w c:\windows\system32\ff_vfw.dll
2009-04-01 20:57 6,313 ----a-w c:\program files\un_Internet Download Manager_16575.txt
2009-03-30 13:47 --------- d-----w c:\documents and settings\amer\Application Data\AVG8
2009-03-28 12:31 --------- d-----w c:\program files\Your Uninstaller 2008
2009-03-27 15:38 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-03-27 15:38 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-03-27 15:38 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-03-27 15:24 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-26 15:35 210,352 ----a-w c:\windows\system32\idmmbc.dll
2009-03-25 22:28 --------- d-----w c:\program files\Kaspersky Lab
2009-03-24 02:28 72,704 ----a-w c:\windows\system32\magnify.exe
2009-03-24 02:27 538,624 ----a-w c:\windows\system32\spider.exe
2009-03-24 02:27 32,768 ----a-w c:\windows\system32\odbcad32.exe
2009-03-24 02:27 142,848 ----a-w c:\windows\system32\mobsync.exe
2009-03-24 02:26 80,384 ----a-w c:\windows\system32\charmap.exe
2009-03-24 02:26 57,344 ----a-w c:\windows\system32\sol.exe
2009-03-24 02:26 215,552 ----a-w c:\windows\system32\osk.exe
2009-03-24 02:26 139,264 ----a-w c:\windows\system32\sndvol32.exe
2009-03-24 02:26 131,072 ----a-w c:\windows\system32\sndrec32.exe
2009-03-24 02:26 114,688 ----a-w c:\windows\system32\calc.exe
2009-03-24 02:24 57,344 ----a-w c:\windows\system32\gpupdate.exe
2009-03-24 02:24 51,200 ----a-w c:\windows\system32\syncapp.exe
2009-03-24 02:24 46,080 ----a-w c:\windows\system32\drwtsn32.exe
2009-03-24 02:24 44,032 ----a-w c:\windows\system32\ipsec6.exe
2009-03-24 02:24 39,424 ----a-w c:\windows\system32\esentutl.exe
2009-03-24 02:24 33,280 ----a-w c:\windows\system32\ping6.exe
2009-03-24 02:24 31,744 ----a-w c:\windows\system32\ntsd.exe
2009-03-24 02:24 25,600 ----a-w c:\windows\system32\routemon.exe
2009-03-24 02:24 22,016 ----a-w c:\windows\system32\mpnotify.exe
2009-03-24 02:24 19,456 ----a-w c:\windows\system32\tcpsvcs.exe
2009-03-24 02:24 19,456 ----a-w c:\windows\system32\arp.exe
2009-03-24 02:24 126,464 ----a-w c:\windows\system32\nwscript.exe
2009-03-24 02:22 69,120 ----a-w c:\windows\system32\notepad.exe
2009-03-24 02:22 677,888 ----a-w c:\windows\system32\mstsc.exe
2009-03-24 02:22 389,120 ----a-w c:\windows\system32\cmd.exe
2009-03-24 02:22 342,016 ----a-w c:\windows\system32\mspaint.exe
2009-03-24 02:22 135,168 ----a-w c:\windows\system32\cscript.exe
2009-03-24 02:22 101,888 ----a-w c:\windows\system32\clipbrd.exe
2009-03-24 02:22 1,204,224 ----a-w c:\windows\system32\ntbackup.exe
2009-03-24 02:21 769,024 ----a-w c:\windows\pchealth\helpctr\binaries\HelpCtr.exe
2009-03-24 02:21 737,280 ----a-w c:\windows\iun6002.exe
2009-03-24 02:21 69,120 ----a-w c:\windows\notepad.exe
2009-03-24 02:21 169,984 ----a-w c:\windows\pchealth\helpctr\binaries\msconfig.exe
2009-03-24 02:21 146,944 ----a-w c:\windows\regedit.exe
2009-03-23 21:30 33,256 ----a-w c:\windows\system32\drivers\hssdrv.sys
2009-03-21 13:40 --------- d-----w c:\documents and settings\Administrator\Application Data\URSoft
2009-03-20 22:27 27,136 ----a-w c:\windows\system32\drivers\tapvpn.sys
2009-03-19 23:07 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-03-19 13:42 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-03-19 12:16 --------- d-----w c:\program files\CCleaner
2009-03-18 20:38 --------- d-----w c:\program files\Common Files\Adobe AIR
2009-03-12 09:37 --------- d-----w c:\program files\Unlocker
2009-02-26 23:19 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-02-26 21:39 --------- d-----w c:\documents and settings\All Users\Application Data\PC Tools
2009-02-26 20:33 --------- d-----w c:\program files\CheckPoint
2009-02-25 12:10 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-02-23 21:57 --------- d-----w c:\program files\Microsoft.NET
2009-02-13 08:31 55,640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-02-09 14:04 1,846,656 ----a-w c:\windows\system32\win32k.sys
2009-01-19 23:32 77,824 ----a-w c:\windows\system32\DRWEBSP.DLL
2008-09-29 16:49 774,144 ----a-w c:\program files\RngInterstitial.dll
2008-09-28 19:00 439,440 ------w c:\program files\un_Internet Download Manager_16575.exe
2008-09-25 16:01 2 --sha-r c:\windows\winstart.bat
.
------- Sigcheck -------
04/14/2008 07:00 PM 14336 6b1139ca38db1678487678c44874b80f c:\windows\system32\svchost.exe
04/14/2008 06:59 PM 578048 f95655e872967ae2cd4c19d8914babb7 c:\windows\system32\user32.dll
03/02/2005 09:19 PM 576512 c287c8218dac8ee3aef1fb2018064699 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
03/08/2007 06:48 PM 577536 adc5a589d00030f03fc315f18eacf05f c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
03/08/2007 06:36 PM 577024 9a432140628841a7d5b489a4ac2eb154 c:\windows\$NtServicePackUninstall$\user32.dll
04/14/2008 06:59 PM 578048 f95655e872967ae2cd4c19d8914babb7 c:\windows\ServicePackFiles\i386\user32.dll
08/03/2004 09:55 PM 576512 ede1d5f29b2752953f3d5d11004154c1 c:\windows\$NtUninstallKB890859$\user32.dll
03/02/2005 09:09 PM 576512 48a5a51ebcd5056a245397e1ea1f78ee c:\windows\$NtUninstallKB925902$\user32.dll
04/14/2008 06:59 PM 82432 8a2b77e2a2f2ad328ee3a2ed91f08ebb c:\windows\system32\ws2_32.dll
08/03/2004 09:56 PM 82944 c3b9fd7b0d0824fc224684b73302a0fd c:\windows\$NtServicePackUninstall$\ws2_32.dll
04/14/2008 06:59 PM 82432 8a2b77e2a2f2ad328ee3a2ed91f08ebb c:\windows\ServicePackFiles\i386\ws2_32.dll
06/20/2008 02:51 PM 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\system32\drivers\tcpip.sys
04/20/2006 02:51 PM 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys
10/30/2007 08:20 PM 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys
04/20/2006 03:18 PM 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
10/30/2007 07:53 PM 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
06/20/2008 01:44 PM 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
06/20/2008 02:51 PM 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
06/20/2008 02:59 PM 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
04/13/2008 10:20 PM 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\tcpip.sys
04/13/2008 10:20 PM 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\$NtUninstallKB951748$\tcpip.sys
08/03/2004 08:14 PM 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB917953$\tcpip.sys
04/14/2008 07:00 PM 506880 bcedf9dccbc807108ce34c9834074c34 c:\windows\system32\winlogon.exe
08/03/2004 09:56 PM 501248 ba4e08425b62be257ae4557da058f1aa c:\windows\$NtServicePackUninstall$\winlogon.exe
04/14/2008 07:00 PM 506880 bcedf9dccbc807108ce34c9834074c34 c:\windows\ServicePackFiles\i386\winlogon.exe
04/13/2008 10:20 PM 182656 1df7f42665c94b825322fae71721130d c:\windows\system32\drivers\ndis.sys
04/13/2008 10:20 PM 182656 1df7f42665c94b825322fae71721130d c:\windows\ServicePackFiles\i386\ndis.sys
04/13/2008 09:53 PM 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\system32\drivers\ip6fw.sys
04/13/2008 09:53 PM 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\ServicePackFiles\i386\ip6fw.sys
08/14/2008 04:20 PM 2025472 d5b1042da019ac12a67b5c69b489f4c1 c:\windows\system32\ntkrnlpa.exe
08/14/2008 04:20 PM 2067584 c0b601d30c9b2e1b2f37423775e26983 c:\windows\Driver Cache\i386\ntkrnlpa.exe
03/02/2005 09:12 PM 2058496 d4bd251b437e841ce93c4afa19b9b788 c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
02/28/2007 07:05 PM 2060928 07ec56eb800a64228a42157d2ff161f3 c:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
08/14/2008 07:24 PM 2067584 5be9c85582d409f6b0520f671b7c4ea7 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
04/14/2008 06:42 PM 2067456 38add7143295f3c2ceae688f4583de30 c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
08/03/2004 10:08 PM 2016768 0cbe3942657196cb871738e5d4a9da79 c:\windows\$NtUninstallKB890859$\ntkrnlpa.exe
04/14/2008 06:42 PM 2025472 732887e7fdc05bed5a79a5ec49fd7e8d c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
03/02/2005 09:06 PM 2016768 facbcf4a5490ea352ad39971c45075f2 c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
08/14/2008 04:20 PM 2146816 fb10a09c0b6e7e596981a5fa86d0c820 c:\windows\system32\ntoskrnl.exe
08/14/2008 04:20 PM 2190720 9d9953c83765c024a5289f625714ed33 c:\windows\Driver Cache\i386\ntoskrnl.exe
03/02/2005 09:12 PM 2181120 c7d8db9c1f072d6e22d9a2b354cce5b2 c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
02/28/2007 07:05 PM 2183680 bd6dea71816e48de42adab538296f596 c:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
08/14/2008 07:24 PM 2190720 8d99acb2cd1a686e7a98cc22119de324 c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
04/14/2008 06:42 PM 2190592 d08babe3cb9fa5c6df025e101b51f76b c:\windows\ServicePackFiles\i386\ntoskrnl.exe
08/03/2004 09:48 PM 2149888 10ac039a4734d143a84763aebacbcd89 c:\windows\$NtUninstallKB890859$\ntoskrnl.exe
04/14/2008 06:42 PM 2146816 1d8896827aaf26d44f6fea9498f296cf c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
03/02/2005 09:06 PM 2137088 69e84522a4f67e3ed23d416fb08888e6 c:\windows\$NtUninstallKB931784$\ntoskrnl.exe
04/14/2008 06:59 PM 1031168 ca3445dce9eb70a2ca2504e0af5c543f c:\windows\Explorer.EXE
06/13/2007 04:10 PM 1030656 d0dc9258122f39129966649085f45880 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
06/13/2007 04:22 PM 1030656 4e877303248a09847fb303ee173fbd70 c:\windows\$NtServicePackUninstall$\explorer.exe
04/14/2008 06:59 PM 1031168 ca3445dce9eb70a2ca2504e0af5c543f c:\windows\ServicePackFiles\i386\explorer.exe
08/03/2004 09:56 PM 1029632 932f97b77f2625f7ff7dfc97552548f8 c:\windows\$NtUninstallKB938828$\explorer.exe
04/14/2008 07:00 PM 108544 940b71d9046a5356e9b5a3cd5a75b064 c:\windows\system32\services.exe
04/14/2008 06:59 PM 13312 99ae1390a271b02d752178df9e8442a3 c:\windows\system32\lsass.exe
04/14/2008 06:59 PM 15360 252f972131eb23596c20b82ca190dc5c c:\windows\system32\ctfmon.exe
04/14/2008 06:59 PM 15360 252f972131eb23596c20b82ca190dc5c c:\windows\ServicePackFiles\i386\ctfmon.exe
04/14/2008 07:00 PM 57856 42eca7ea7d2e8b874bb9e4d147a5f783 c:\windows\system32\spoolsv.exe
04/14/2008 07:00 PM 26112 b2b4e4722caafe109bec13773bcb75b0 c:\windows\system32\userinit.exe
04/14/2008 07:00 PM 26112 b2b4e4722caafe109bec13773bcb75b0 c:\windows\ServicePackFiles\i386\userinit.exe
04/14/2008 06:59 PM 295424 58e202572d3251bf2687bf841ea00ce0 c:\windows\system32\termsrv.dll
08/04/2004 12:55 AM 295424 4d42fe6f795dea7917f329a40a175294 c:\windows\$NtServicePackUninstall$\termsrv.dll
04/14/2008 06:59 PM 295424 58e202572d3251bf2687bf841ea00ce0 c:\windows\ServicePackFiles\i386\termsrv.dll
04/14/2008 06:59 PM 1357824 94ebb9e7d65fda05e515d6b70e4247e2 c:\windows\system32\kernel32.dll
08/03/2004 09:55 PM 1351680 458f1764a02b43a053d0e2cef2a6ae5b c:\windows\$NtUninstallKB935839$\kernel32.dll
04/16/2007 07:09 PM 1354240 e231223e2bc28a0c7732e5df968b3afe c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
04/14/2008 06:59 PM 1357824 94ebb9e7d65fda05e515d6b70e4247e2 c:\windows\ServicePackFiles\i386\kernel32.dll
04/14/2008 06:59 PM 17408 dc4cd0aad9a26c4fb63d75fb54fdfda7 c:\windows\system32\powrprof.dll
08/03/2004 09:55 PM 17408 a8c31d5b403b48e98f352dcbcfceeb9e c:\windows\$NtServicePackUninstall$\powrprof.dll
04/14/2008 06:59 PM 17408 dc4cd0aad9a26c4fb63d75fb54fdfda7 c:\windows\ServicePackFiles\i386\powrprof.dll
04/14/2008 06:59 PM 110080 437820b0db7a11fb58660ce6c40a05f6 c:\windows\system32\imm32.dll
08/03/2004 09:55 PM 110080 e3fe07e893352f48748790da6fd04a42 c:\windows\$NtServicePackUninstall$\imm32.dll
04/14/2008 06:59 PM 110080 437820b0db7a11fb58660ce6c40a05f6 c:\windows\ServicePackFiles\i386\imm32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [03/30/2009 06:43 PM 2790832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [03/27/2009 06:38 PM 206088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [05/13/2008 09:13 AM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonuiX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
12/22/2008 11:05 AM 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0sremcon.exe\
0SsiEfr.exe
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
backup=c:\windows\pss\PalTalk.lnkCommon Startup
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalTalk.lnk
[HKLM\~\startupfolder\C:^Documents and Settings^amer^قائمة ابدأ^البرامج^بدء التشغيل^Internet Download Manager.lnk]
path=c:\documents and settings\amer\قائمة ابدأ\البرامج\بدء التشغيل\Internet Download Manager.lnk
backup=c:\windows\pss\Internet Download Manager.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 02/27/2009 05:10 PM 35696 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 04/14/2008 06:59 PM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
-ra------ 05/11/2007 10:47 AM 790528 c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--------- 03/30/2009 06:43 PM 2790832 c:\program files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 03/24/2009 05:20 AM 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 04/11/2008 09:10 PM 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
--a------ 03/24/2009 05:19 AM 15872 c:\program files\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Paltalk Messenger\\PALTALK.EXE"=
"c:\\WINDOWS\\system32\\wjview.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVLibraryService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVGuideDataLoader.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVSettingsService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVTaskManagerService.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16562:TCP"= 16562:TCP:BitComet 16562 TCP
"16562:UDP"= 16562:UDP:BitComet 16562 UDP
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [2008-06-02 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [2008-06-02 52224]
R1 mchInjDrv;madCodeHook DLL injection driver;c:\windows\system32\drivers\mchInjDrv.sys [2009-01-31 2560]
R2 Prvflder;Prvflder;c:\windows\system32\drivers\prvflder.sys [2006-04-21 70912]
R3 HssDrv;HssDrv;c:\windows\system32\drivers\hssdrv.sys [2009-01-30 33256]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-03-13 26640]
S0 WINSEC;WINSEC;c:\windows\system32\drivers\WINSEC.SYS --> c:\windows\system32\drivers\WINSEC.SYS [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS --> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S2 HssSrv;HssSrv; [x]
S2 setup_7.0.0.180_21.04.2008_09-43;setup_7.0.0.180_21.04.2008_09-43; [x]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-10-03 33752]
S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS --> c:\program files\SUPERAntiSpyware\SASENUM.SYS [?]
S3 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S4 winser;winser;c:\windows\system32\winsersec.exe --> c:\windows\system32\winsersec.exe [?]
.
Contents of the 'Scheduled Tasks' folder
2009-01-05 c:\windows\Tasks\One-Click Tweak.job
- c:\program files\Advanced PC Tweaker\OneClick.exe []
2009-04-11 c:\windows\Tasks\PCConfidential.job
- c:\program files\Winferno\PC Confidential\PCConfidential.exe []
2009-04-11 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [12/31/2008 05:04 PM]
2009-03-24 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [12/31/2008 05:04 PM]
.
- - - - ORPHANS REMOVED - - - -
BHO-{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - (no file)
MSConfigStartUp-AFProg - c:\program files\AnchorFree\bin\ctrl\AFController.exe
MSConfigStartUp-protect_autorun - c:\docume~1\amer\LOCALS~1\Temp\ir_ext_temp_0\AutoPlay\Docs\CPE17AntiAutoruna.exe
MSConfigStartUp-USB Antivirus - c:\program files\USB Disk Security\USBGuard.exe
.
------- Supplementary Scan -------
.
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyOverride = <local>
IE: إضافة إلى حاجب إعلان الشعار - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
LSP: c:\windows\system32\idmmbc.dll
FF - ProfilePath - c:\documents and settings\amer\Application Data\Mozilla\Firefox\Profiles\ahkilsvj.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sa/
FF - component: c:\documents and settings\amer\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
.
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-11 22:31:54
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-220523388-1960408961-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4D367ED2-6D33-289C-F529-3048B5B9F254}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jagipknddingfobkicij"=hex:62,61,63,67,00,00
"jagipknddingfobkicej"=hex:62,61,67,67,00,00
"iagjbkejbaiokacdja"=hex:6b,61,68,67,6e,61,6c,67,65,67,64,6c,6f,67,6e,6e,65,66,
69,61,66,61,00,00
"hacilkglofbjaana"=hex:61,62,68,6a,62,67,67,6f,6f,67,69,6e,63,61,70,6b,68,61,
69,65,62,67,6c,63,6f,64,69,6c,63,70,67,64,70,61,00,00
"jabigkmlkaadegkifcgg"=hex:64,62,6c,69,6b,68,70,62,63,6b,70,64,64,65,66,6c,6f,
6f,6f,66,67,65,6a,6a,6a,62,62,6c,65,64,6a,6a,6c,6d,66,68,65,6b,67,69,00,00
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):f8,fe,29,60,f0,e5,ba,20,24,e8,dc,c0,7a,69,a2,50,69,19,db,a2,d3,
99,a8,07,3c,1f,72,5a,cb,a8,78,56,1a,f4,ba,8c,d0,90,e6,6f,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):da,80,78,15,87,3c,a2,8b,8d,38,63,e1,16,06,6d,0b,8d,85,60,ed,fa,
e6,84,e7,8d,54,de,f6,7d,16,b6,95,c4,1f,31,59,8e,35,6a,5b,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ac9bc4a6-f612-4cdf-9ed5-73ffc692e805}]
@Denied: (Full) (Everyone)
"Model"=dword:00000150
"Therad"=dword:00000029
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{d49a7d95-9ace-48de-b9ff-386855289108}]
@Denied: (Full) (Everyone)
"Model"=dword:00000013
"Therad"=dword:0000000f
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,27,b9,7e,3f,69,
3c,cc,a9,05,98,32,02,34,2b,da,61,4f,a7,3c,25,58,45,83,cd,d3,79,22,18,3a,ef,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(836)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'lsass.exe'(892)
c:\windows\system32\idmmbc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\VERCLSID.EXE
.
**************************************************************************
.
Completion time: 04/11/2009 22:34:20 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-11 19:34:16
Pre-Run: 3,715,989,504 bytes free
Post-Run: 3,657,039,872 bytes free
366 --- E O F --- 2009-04-04 17:21:39