ComboFix 09-04-18.05 - Administrator 04/18/2009 15:04.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.967.1025.18.2039.1598 [GMT 3:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\kb905474_1.5.540.0.exe
.
((((((((((((((((((((((((( Files Created from 2009-03-18 to 2009-04-18 )))))))))))))))))))))))))))))))
.
2009-04-15 13:35 . 2008-04-21 21:26 215040 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-13 22:28 . 2009-04-13 22:28 -------- d-----w c:\windows\system32\KB905474
2009-04-13 22:28 . 2009-03-10 19:26 1430400 ----a-w c:\windows\system32\KB905474\wganotifypackageinner.exe
2009-04-13 22:28 . 2009-03-10 19:18 453000 ----a-w c:\windows\system32\KB905474\wgasetup.exe
2009-04-13 22:28 . 2009-02-09 15:51 11874 ----a-w c:\windows\system32\KB905474\wga_eula.txt
2009-04-02 22:25 . 2009-04-02 22:25 -------- d-----w c:\program files\Common Files\xing shared
2009-03-21 14:19 . 2009-03-21 14:19 1354240 -c----w c:\windows\system32\dllcache\kernel32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-18 12:07 . 2009-03-08 10:04 22308640 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-18 12:07 . 2009-03-08 10:04 336672 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-18 11:59 . 2009-03-08 10:04 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-18 11:13 . 2001-09-19 12:00 62470 ----a-w c:\windows\system32\perfc001.dat
2009-04-18 11:13 . 2001-09-19 12:00 337218 ----a-w c:\windows\system32\perfh001.dat
2009-04-17 23:19 . 2009-03-08 10:04 33032 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-17 23:19 . 2009-03-08 10:04 301508 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-09 21:51 . 2008-12-21 21:03 25275 ----a-w C:\YServer.txt
2009-04-02 22:25 . 2008-04-02 17:23 -------- d-----w c:\program files\Common Files\Real
2009-03-31 18:52 . 2008-12-19 21:46 230432 ----a-w C:\PA7302.DAT
2009-03-09 11:19 . 2008-04-02 16:00 29488 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-09 11:18 . 2008-04-02 17:24 -------- d-----w c:\program files\Windows Live
2009-03-09 11:15 . 2009-03-09 11:15 -------- d-----w c:\program files\Microsoft Sync Framework
2009-03-09 11:14 . 2009-03-09 11:14 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-03-09 11:12 . 2009-03-09 11:12 -------- d-----w c:\program files\Microsoft
2009-03-09 11:12 . 2009-03-09 11:12 -------- d-----w c:\program files\Windows Live SkyDrive
2009-03-09 10:20 . 2009-03-09 10:20 1182056 ----a-w C:\wlsetup-web.exe
2009-03-08 21:18 . 2009-03-08 21:18 -------- d-----w c:\program files\Common Files\Windows Live
2009-03-08 14:48 . 2009-02-24 20:08 -------- d-----w c:\program files\Windows Media Connect 2
2009-03-08 10:55 . 2009-03-08 10:55 1086038 ----a-w C:\1143871521_WinRAR- 3.51a.zip
2009-03-08 10:37 . 2009-03-08 10:04 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-03-08 10:37 . 2009-03-08 10:04 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-03-08 10:37 . 2007-10-31 10:41 112144 ----a-w c:\windows\system32\drivers\kl1.sys
2009-03-08 10:04 . 2008-04-02 16:02 -------- d-----w c:\program files\Kaspersky Lab
2009-03-08 10:03 . 2008-12-21 13:55 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-03-08 10:00 . 2009-02-28 11:17 -------- d-----w c:\program files\Common Files\BitDefender
2009-03-08 09:59 . 2009-02-28 11:17 -------- d-----w c:\documents and settings\All Users\Application Data\BitDefender
2009-03-06 14:44 . 2004-08-03 21:55 282624 ----a-w c:\windows\system32\pdh.dll
2009-02-26 22:13 . 2008-04-09 16:18 -------- d-----w c:\program files\Google
2009-02-21 16:03 . 2009-02-21 16:02 -------- d-----w c:\program files\Java
2009-02-21 15:58 . 2009-02-21 15:58 -------- d-----w c:\program files\Common Files\Java
2009-02-20 08:29 . 2004-08-03 21:55 657920 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:29 . 2004-08-03 21:55 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 14:15 . 2004-08-03 21:46 1846144 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:48 . 2004-08-04 00:48 2017280 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:48 . 2004-08-03 21:48 2137600 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 10:19 . 2004-08-03 21:55 399360 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:19 . 2004-08-03 21:55 717824 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:19 . 2004-08-03 21:55 680960 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:19 . 2004-08-03 21:55 693760 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 10:05 . 2004-08-03 21:56 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 16:54 . 2001-09-19 12:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 16:43 . 2009-02-06 16:43 307576 ----a-w c:\windows\WLXPGSS.SCR
2009-02-06 15:52 . 2009-02-06 15:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-03 20:08 . 2004-08-03 21:55 55808 ----a-w c:\windows\system32\secur32.dll
2008-11-18 09:19 . 2008-11-18 09:19 136 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2006-10-11 08:2008-07-03 15:16 04:58 . c:\program files\mozilla firefox\components\jar50.dll
2006-10-11 08:2008-07-03 15:16 04:59 . c:\program files\mozilla firefox\components\jsd3250.dll
2006-10-11 08:2008-07-03 15:16 05:03 . c:\program files\mozilla firefox\components\myspell.dll
2006-10-11 08:2008-07-03 15:16 05:03 . c:\program files\mozilla firefox\components\spellchk.dll
2006-10-11 08:2008-07-03 15:16 04:58 . c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{930f1200-f5f1-4870-bac6-e233ec8e7023}"= "c:\program files\Softonic_English\tbSoft.dll" [2008-07-27 1606680]
[HKEY_CLASSES_ROOT\clsid\{930f1200-f5f1-4870-bac6-e233ec8e7023}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{930f1200-f5f1-4870-bac6-e233ec8e7023}]
2008-07-27 18:11 1606680 ----a-w c:\program files\Softonic_English\tbSoft.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{930f1200-f5f1-4870-bac6-e233ec8e7023}"= "c:\program files\Softonic_English\tbSoft.dll" [2008-07-27 1606680]
[HKEY_CLASSES_ROOT\clsid\{930f1200-f5f1-4870-bac6-e233ec8e7023}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{930F1200-F5F1-4870-BAC6-E233EC8E7023}"= "c:\program files\Softonic_English\tbSoft.dll" [2008-07-27 1606680]
[HKEY_CLASSES_ROOT\clsid\{930f1200-f5f1-4870-bac6-e233ec8e7023}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-23 68856]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-27 4670968]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-05 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-05 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-05 114688]
"StormCodec_Helper"="c:\program files\Ringz Studio\Storm Codec\StormSet.exe" [2005-02-07 94037]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"QuickTime Task"="c:\program files\Ringz Studio\Storm Codec\qttask.exe" [2008-11-17 155648]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_19\bin\jusched.exe" [2008-11-09 32881]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-02 180269]
"PROMon.exe"="PROMon.exe" - c:\windows\system32\PROMon.exe [2002-04-18 73728]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-06-13 16377344]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2008-4-2 1183744]
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Media Player.lnk]
path=c:\documents and settings\Administrator\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Media Player.lnk
backup=c:\windows\pss\Adobe Media Player.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsgCenterExe]
2009-03-18 15:16 69688 ----a-w c:\program files\Common Files\Real\Update_OB\RealOneMessageCenter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-02-06 15:53 3885408 ----a-w c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2008-04-23 14:54 22185768 ----a-r c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2007-03-27 12:22 4670968 ----a-w c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
R2 BulkUsb;Genius ColorPage USB Scanner;c:\windows\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
R2 OMSCAN;OMSCAN; [x]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-12-13 24592]
S3 PAC7302;PAC7302 VGA USB Camera;c:\windows\system32\DRIVERS\PAC7302.SYS [2007-06-14 457856]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0de8fe5e-454b-11dd-ae7a-001d92289e52}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f1064eb4-ce7d-11dd-9d54-001d92289e52}]
\Shell\AutoRun\command - wscript.exe antinul.vbe
\Shell\open\Command - wscript.exe antinul.vbe
.
Contents of the 'Scheduled Tasks' folder
2009-04-18 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-13 19:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.maktoob.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: Microsoft XML Parser for Java -
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-18 15:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OMSCAN]
"ImagePath"="\Sys"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(892)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(948)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll
.
Completion time: 2009-04-18 15:08
ComboFix-quarantined-files.txt 2009-04-18 12:08
Pre-Run: 50,372,964,352 bytes free
Post-Run: 50,641,137,664 bytes free
186 --- E O F --- 2009-04-15 13:41