ComboFix 09-05-02.4 - بوفاضل 05/02/2009 18:43.4 - NTFSx86 MINIMALMicrosoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.446.273 [GMT 3:00]Running from: c:\documents and settings\بوفاضل\سطح المكتب\ComboFix.exeWARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.((((((((((((((((((((((((( Files Created from 2009-04-02 to 2009-05-02 ))))))))))))))))))))))))))))))).2009-05-02 09:34 . 2009-05-02 10:01 32 --sha-w c:\windows\system32\drivers\fidbox2.dat2009-05-02 09:34 . 2009-05-02 10:01 32 --sha-w c:\windows\system32\drivers\fidbox.dat2009-04-29 08:15 . 2009-04-29 08:15 -------- d-----w c:\documents and settings\Administrator\سطح المكتب2009-04-29 08:15 . 2009-04-29 08:15 -------- d-----w c:\documents and settings\Administrator\قائمة ابدأ2009-04-29 08:15 . 2009-04-29 08:15 -------- d-----w c:\documents and settings\Administrator2009-04-28 21:04 . 2009-04-28 21:29 -------- d-----w c:\documents and settings\بوفاضل\DoctorWeb2009-04-28 21:04 . 2009-04-28 21:29 -------- d-----w c:\documents and settings\بوفاضل\DoctorWeb2009-04-28 11:43 . 2009-04-28 11:43 -------- d-sh--w C:\found.0042009-04-28 11:30 . 2009-04-28 11:30 -------- d-----w c:\documents and settings\بوفاضل\Application Data\CyberScrub2009-04-28 11:29 . 2009-05-02 10:00 -------- d-----w c:\documents and settings\بوفاضل\Application Data\cleaner2009-04-28 10:02 . 2009-04-28 10:37 -------- d-----w c:\windows\BDOSCAN82009-04-23 16:15 . 2009-03-10 19:18 453000 ----a-w c:\windows\system32\KB905474\wgasetup.exe2009-04-23 16:15 . 2009-04-24 09:41 -------- d-----w c:\windows\system32\KB9054742009-04-21 20:21 . 2009-04-21 20:21 -------- d-sh--w C:\found.0032009-04-19 15:12 . 2009-04-19 15:12 -------- d-----w c:\documents and settings\بوفاضل\Local Settings\Application Data\PGP Corporation2009-04-19 15:12 . 2009-04-19 15:12 -------- d-----w c:\documents and settings\بوفاضل\Application Data\PGP Corporation2009-04-19 15:12 . 2009-04-19 15:12 -------- d-----w c:\documents and settings\All Users\Application Data\PGP Corporation2009-04-16 13:38 . 2009-04-16 13:38 -------- d-----w c:\program files\Lavalys2009-04-16 13:38 . 2009-05-01 21:09 -------- d-----w c:\program files\AviSynth 2.52009-04-16 13:38 . 2009-04-16 13:42 -------- d-----w c:\program files\Easy RealMedia Tools2009-04-16 13:37 . 2009-05-01 21:19 -------- d-----w c:\documents and settings\بوفاضل\Local Settings\Application Data\WinAVI2009-04-16 13:36 . 2009-04-16 13:36 -------- d-----w c:\program files\WinAVI Video Converter 9.02009-04-16 13:36 . 2009-04-16 13:36 -------- d-----w c:\windows\WinAVI Video Converter 9.02009-04-16 13:02 . 2009-04-16 13:02 -------- d-sh--w c:\windows\ftpcache2009-04-16 13:02 . 2009-04-16 13:02 -------- d-----w c:\program files\FLV-Media Player2009-04-16 13:00 . 2009-05-01 15:20 -------- d-----w c:\documents and settings\بوفاضل\Application Data\Video Converter for Any Flv Player2009-04-16 13:00 . 2009-05-01 15:20 -------- d-----w c:\program files\Any Flv Player2009-04-16 12:48 . 2009-04-16 12:48 -------- d-----w c:\documents and settings\بوفاضل\Application Data\FLVPlayer4Free2009-04-16 12:32 . 2009-04-16 12:32 275456 ----a-w c:\windows\system32\gfbaksm.dll2009-04-16 12:32 . 2009-04-16 12:32 275456 ----a-w c:\windows\system32\gfbaksm.dat2009-04-16 12:32 . 2009-04-16 12:33 -------- d-----w c:\program files\GetFLV2009-04-09 21:53 . 2009-05-01 14:08 -------- d-----w c:\documents and settings\All Users\Application Data\Avira2009-04-06 16:27 . 2009-04-06 16:27 -------- d-----w c:\program files\TechSmith2009-04-06 15:57 . 2009-04-06 16:02 -------- d-----w c:\program files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter2009-04-06 15:49 . 2009-04-06 15:49 -------- d-----w C:\Mp3 Output2009-04-06 15:49 . 2007-02-25 12:36 383238 ----a-w c:\windows\system32\libmp3lame-0.dll2009-04-06 15:49 . 2009-04-06 15:49 -------- d-----w c:\program files\Smallvideosoft2009-04-05 08:26 . 2009-04-05 08:26 -------- d-sh--w C:\found.002.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2009-05-02 15:37 . 2008-08-06 08:03 6 ---ha-w c:\windows\Tasks\SA.DAT2009-05-02 15:00 . 2009-02-06 15:04 260 ---ha-w c:\windows\Tasks\ACDDA2FA918A5512.job2009-05-02 10:01 . 2009-05-02 09:34 32 --sha-w c:\windows\system32\drivers\fidbox2.idx2009-05-02 10:01 . 2009-05-02 09:34 32 --sha-w c:\windows\system32\drivers\fidbox.idx2009-05-02 09:23 . 2008-08-07 04:40 -------- d-----w c:\program files\Kaspersky Lab2009-05-01 20:59 . 2008-11-16 21:45 -------- d-----w c:\program files\YCIII2009-05-01 16:49 . 2008-09-06 20:14 424 ---ha-w c:\windows\Tasks\User_Feed_Synchronization-{8BB6EAE7-E840-45A3-BB97-672FB2F53D5F}.job2009-05-01 09:41 . 2001-09-19 12:00 59628 ----a-w c:\windows\system32\perfc001.dat2009-05-01 09:41 . 2001-09-19 12:00 331398 ----a-w c:\windows\system32\perfh001.dat2009-04-28 11:44 . 2008-10-05 01:35 -------- d-----w c:\program files\Yahoo!2009-04-22 13:42 . 2008-08-07 02:59 -------- d-----w c:\program files\MSN Messenger2009-04-22 13:41 . 2008-09-03 01:18 -------- d-----w c:\program files\Messenger Plus! Live2009-04-09 22:34 . 2009-01-01 21:55 -------- d-----w c:\program files\Malwarebytes' Anti-Malware2009-04-06 12:32 . 2009-01-01 21:55 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys2009-04-06 12:32 . 2009-01-01 21:55 15504 ----a-w c:\windows\system32\drivers\mbam.sys2009-03-28 06:02 . 2008-08-08 11:52 116904 ----a-w c:\documents and settings\بوفاضل\Local Settings\Application Data\GDIPFONTCACHEV1.DAT2009-03-27 16:16 . 2009-03-27 16:16 -------- d-----w c:\program files\MSECache2009-03-27 15:35 . 2008-09-03 01:17 -------- d-----w c:\program files\Windows Live2009-03-27 15:34 . 2009-03-27 15:34 -------- d-----w c:\program files\Microsoft Sync Framework2009-03-27 15:33 . 2009-03-27 15:33 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition2009-03-27 15:30 . 2009-03-27 15:30 -------- d-----w c:\program files\Microsoft2009-03-27 15:30 . 2009-03-27 15:30 -------- d-----w c:\program files\Windows Live SkyDrive2009-03-06 14:20 . 2008-04-14 18:29 283136 ----a-w c:\windows\system32\pdh.dll2009-03-04 17:55 . 2009-03-04 17:55 410984 ----a-w c:\windows\system32\deploytk.dll2009-03-04 17:55 . 2008-09-29 10:08 -------- d-----w c:\program files\Java2009-03-03 00:06 . 2008-07-20 10:51 826368 ----a-w c:\windows\system32\wininet.dll2009-02-26 23:48 . 2008-12-10 11:48 74490 ----a-w c:\windows\Uninstal.exe2009-02-20 16:50 . 2008-07-20 10:50 78336 ----a-w c:\windows\system32\ieencode.dll2009-02-10 16:03 . 2008-04-14 18:12 2067584 ----a-w c:\windows\system32\ntkrnlpa.exe2009-02-09 14:04 . 2008-04-14 18:07 1846656 ----a-w c:\windows\system32\win32k.sys2009-02-09 13:40 . 2009-02-07 15:52 592 ----a-w c:\windows\chgkey.vbs2009-02-09 11:22 . 2008-04-14 18:12 2190592 ----a-w c:\windows\system32\ntoskrnl.exe2009-02-09 11:21 . 2008-04-14 18:30 110592 ----a-w c:\windows\system32\services.exe2009-02-09 10:51 . 2008-04-14 18:29 723456 ----a-w c:\windows\system32\lsasrv.dll2009-02-09 10:51 . 2008-04-14 18:29 401408 ----a-w c:\windows\system32\rpcss.dll2009-02-09 10:51 . 2008-04-14 18:29 681472 ----a-w c:\windows\system32\advapi32.dll2009-02-09 10:51 . 2008-04-14 18:29 693760 ----a-w c:\windows\system32\ntdll.dll2009-02-06 16:43 . 2009-02-06 16:43 307576 ----a-w c:\windows\WLXPGSS.SCR2009-02-06 15:52 . 2009-02-06 15:52 49504 ----a-w c:\windows\system32\sirenacm.dll2009-02-06 10:39 . 2001-09-19 12:00 35328 ----a-w c:\windows\system32\sc.exe2009-02-03 19:57 . 2008-04-14 18:29 56832 ----a-w c:\windows\system32\secur32.dll.------- Sigcheck -------[-] 2008-07-20 10:56 1571328 E16DB203BFEB9740C8483E418C8C18AD c:\windows\system32\sfcfiles.dll.((((((((((((((((((((((((((((( SnapShot_2009-04-30_12.46.30 ))))))))))))))))))))))))))))))))))))))))).- 2001-09-19 12:00 . 2009-04-28 17:27 59638 c:\windows\system32\perfc009.dat+ 2001-09-19 12:00 . 2009-05-01 09:41 59638 c:\windows\system32\perfc009.dat+ 2001-09-19 12:00 . 2009-05-01 09:41 395398 c:\windows\system32\perfh009.dat- 2001-09-19 12:00 . 2009-04-28 17:27 395398 c:\windows\system32\perfh009.dat+ 2008-11-11 17:00 . 2008-11-11 17:00 218376 c:\windows\system32\klogon.dll+ 2009-05-01 15:48 . 2009-05-01 16:22 226832 c:\windows\system32\drivers\klif.sys+ 2008-07-21 14:34 . 2008-07-21 14:34 121872 c:\windows\system32\drivers\kl1.sys.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-25 8433664]"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-02 185872]"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-08-07 98304]"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]"nltide_2"="shell32" [X][HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Speed Launch.lnk]path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Reader Speed Launch.lnkbackup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Microsoft Office OneNote 2003 Quick Launch.lnk]path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Microsoft Office OneNote 2003 Quick Launch.lnkbackup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkCommon Startup[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^WinZip Quick Pick.lnk]path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\WinZip Quick Pick.lnkbackup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup[HKLM\~\startupfolder\C:^Documents and Settings^بوفاضل^قائمة ابدأ^البرامج^بدء التشغيل^Yankee Clipper III.lnk]path=c:\documents and settings\بوفاضل\قائمة ابدأ\البرامج\بدء التشغيل\Yankee Clipper III.lnkbackup=c:\windows\pss\Yankee Clipper III.lnkStartup[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]"WMPNetworkSvc"=3 (0x3)"usnjsvc"=3 (0x3)"RichVideo"=2 (0x2)"ose"=3 (0x3)"OracleXETNSListener"=2 (0x2)"OracleXEClrAgent"=3 (0x3)"OracleServiceXE"=2 (0x2)"OracleMTSRecoveryService"=3 (0x3)"MDM"=2 (0x2)"IDriverT"=3 (0x3)"gusvc"=3 (0x3)"AVP"=2 (0x2)"AgereModemAudio"=2 (0x2)[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\system32\\sessmgr.exe"="c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe"="c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"="c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="c:\\Program Files\\Messenger\\msmsgs.exe"=R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]R3 hidshim;Service for HID-KMDF Shim layer;c:\windows\system32\DRIVERS\hidshim.sys [2007-07-20 5632]R3 winbondhidcir;Winbond HID CIR Receiver;c:\windows\system32\DRIVERS\winbondhidcir.sys [2007-07-20 21504]R4 OracleJobSchedulerXE;OracleJobSchedulerXE; [x]R4 OracleServiceXE;OracleServiceXE; [x]R4 OracleXETNSListener;OracleXETNSListener;c:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe [2006-02-01 204800][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5abdb341-a430-11dd-8d5c-001b24ee22c5}]\Shell\AutoRun\command - F:\zPharaoh.exe\Shell\explore\command - F:\zPharaoh.exe\Shell\open\command - F:\zPharaoh.exe[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f49c9904-67b7-11dd-8c06-001b24ee22c5}]\Shell\AutoRun\command - f:\ctrun\start.exe\Shell\readme\command - notepad \readme.txt.Contents of the 'Scheduled Tasks' folder2009-05-01 c:\windows\Tasks\User_Feed_Synchronization-{8BB6EAE7-E840-45A3-BB97-672FB2F53D5F}.job- c:\windows\system32\msfeedssync.exe [2008-07-20 10:50]..------- Supplementary Scan -------.uStart Page = hxxp://www.google.com.sa/IE: Download ALL with IDAIE: Download with IDAIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cabFF - ProfilePath - c:\documents and settings\بوفاضل\Application Data\Mozilla\Firefox\Profiles\1dogw6dj.default\FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=FF - prefs.js: browser.search.selectedEngine - YahooFF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/?linkid=9529939FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=en-CA&FORM=MICFEC&q=FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dllFF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll.**************************************************************************catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
scan 2009-05-02 18:45Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfullyhidden files: 0**************************************************************************.--------------------- LOCKED REGISTRY KEYS ---------------------[HKEY_USERS\S-1-5-21-1708537768-1202660629-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*t*t* \OpenWithList]@Class="Shell""a"="msnmsgr.exe""MRUList"="a"[HKEY_USERS\S-1-5-21-1708537768-1202660629-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B98EC8F3-C72D-17F0-F729-48FBEB943424}*]@Allowed: (Read) (RestrictedCode)@Allowed: (Read) (RestrictedCode)"fajjenaeimka"=hex:66,61,68,6d,68,66,6c,6b,6c,6a,66,6b,00,00[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\WPAEvents]@Denied: (Full) (LocalSystem)"OOBETimer"=hex:ff,d5,71,d6,8b,6a,8d,6f,d5,33,93,fd.--------------------- DLLs Loaded Under Running Processes ---------------------- - - - - - - > 'explorer.exe'(2032)c:\progra~1\MICROS~2\OFFICE11\MCPS.DLL.Completion time: 2009-05-02 18:47ComboFix-quarantined-files.txt 2009-05-02 15:47ComboFix2.txt 2009-05-02 15:35ComboFix3.txt 2009-04-30 13:04ComboFix4.txt 2009-04-28 12:03Pre-Run: 29,632,540,672 bytes freePost-Run: 29,628,575,744 bytes free226 --- E O F --- 2009-04-30 12:35