ComboFix 09-05-07.01 - OMAR 05/07/2009 19:57.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.479.188 [GMT 3:00]
Running from: c:\documents and settings\OMAR\My Documents\Downloads\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
FW: Kaspersky Anti-Virus *disabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\FunWebProducts
c:\windows\system32\kakle.dll
c:\windows\system32\systeminfo.dll
c:\windows\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-07 to 2009-05-07 )))))))))))))))))))))))))))))))
.
2009-05-07 14:39 . 2009-05-07 14:39 -------- d-----w c:\documents and settings\OMAR\Application Data\QuickScan
2009-05-06 18:08 . 2009-05-06 18:08 -------- d-sh--w C:\FOUND.016
2009-05-05 06:54 . 2009-05-05 06:54 -------- d-sh--w C:\FOUND.015
2009-05-04 12:34 . 2009-05-04 12:34 -------- d-----w c:\program files\Common Files\Adobe
2009-05-03 11:15 . 2009-05-03 11:15 -------- d-----w c:\program files\SWfX v2.0
2009-05-03 10:44 . 2009-05-03 10:44 -------- d-----w c:\program files\Easy GIF Animator
2009-05-03 03:28 . 2009-05-03 09:27 177 ----a-w C:\DelUS.bat
2009-05-02 17:24 . 2009-05-02 17:24 -------- d-----w c:\documents and settings\OMAR\Application Data\JLC's Software
2009-04-30 22:03 . 2009-04-30 22:03 -------- d-sh--w C:\FOUND.014
2009-04-30 04:18 . 2009-04-30 04:18 -------- d-----w c:\documents and settings\OMAR\Application Data\IDM
2009-04-30 04:18 . 2009-04-30 04:18 -------- d-----w c:\program files\Internet Download Manager
2009-04-29 12:20 . 2009-03-26 15:35 210352 ----a-w c:\windows\system32\idmmbc.dll
2009-04-26 12:06 . 2009-04-26 13:11 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-04-26 12:06 . 2009-04-26 13:11 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-04-26 12:05 . 2009-05-07 17:04 7200 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-26 12:05 . 2009-05-07 17:04 32 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-26 12:05 . 2009-04-26 12:05 -------- d-----w c:\program files\Kaspersky Lab
2009-04-26 12:05 . 2009-04-26 12:05 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-24 22:18 . 2009-04-24 22:18 -------- d-----w C:\Temp
2009-04-24 15:27 . 2009-04-24 15:27 -------- d-sh--w C:\FOUND.013
2009-04-23 11:22 . 2009-04-23 11:22 -------- d-sh--w C:\FOUND.012
2009-04-22 21:18 . 2009-04-22 21:18 -------- d-----w c:\program files\vSoft
2009-04-22 19:03 . 2009-04-22 19:03 -------- d-----w c:\documents and settings\OMAR\Local Settings\Application Data\Google
2009-04-22 14:01 . 2009-04-22 14:01 -------- d--h--w c:\windows\PIF
2009-04-22 07:06 . 2009-04-22 07:06 -------- d-sh--w C:\FOUND.011
2009-04-20 04:40 . 2009-04-20 04:40 -------- d-sh--w C:\FOUND.010
2009-04-19 12:10 . 2009-04-19 12:10 -------- d-----w c:\windows\F20A984B9B304A9EA3AC918AF0D85A48.TMP
2009-04-19 11:16 . 2009-04-19 11:16 -------- d-----w c:\program files\DaemonTools_WhenUSave_Installer
2009-04-19 11:14 . 2009-04-19 11:14 -------- d-----w c:\program files\DAEMON Tools
2009-04-19 11:12 . 2009-04-19 11:12 682232 ----a-w c:\windows\system32\drivers\sptd.sys
2009-04-19 10:12 . 2009-04-19 10:12 -------- d-sh--w C:\FOUND.009
2009-04-19 06:33 . 2009-04-19 06:33 -------- d-sh--w C:\FOUND.008
2009-04-17 15:20 . 2009-02-09 10:20 616960 ----a-w c:\windows\system32\advapi32.dll
2009-04-17 15:20 . 2009-02-09 10:20 723456 ----a-w c:\windows\system32\lsasrv.dll
2009-04-17 15:20 . 2009-02-09 10:20 714752 ----a-w c:\windows\system32\ntdll.dll
2009-04-17 15:20 . 2009-02-06 17:14 110592 ----a-w c:\windows\system32\services.exe
2009-04-17 15:20 . 2009-02-06 16:49 2057728 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-04-17 15:20 . 2009-02-06 17:24 2180480 ----a-w c:\windows\system32\ntoskrnl.exe
2009-04-13 21:03 . 2009-04-13 21:03 -------- d-----w c:\program files\Combined Community Codec Pack
2009-04-12 15:15 . 2004-01-25 16:18 217088 ----a-w c:\windows\system32\yv12vfw.dll
2009-04-12 15:15 . 2008-12-07 18:08 795648 ----a-w c:\windows\system32\xvidcore.dll
2009-04-12 15:15 . 2008-12-07 18:08 130048 ----a-w c:\windows\system32\xvidvfw.dll
2009-04-12 15:15 . 2008-11-06 16:37 3596288 ----a-w c:\windows\system32\qt-dx331.dll
2009-04-12 15:15 . 2008-12-11 00:33 86016 ----a-w c:\windows\system32\dpl100.dll
2009-04-12 15:15 . 2008-11-06 16:33 684032 ----a-w c:\windows\system32\divx.dll
2009-04-12 15:15 . 2009-04-02 12:21 84480 ----a-w c:\windows\system32\ff_vfw.dll
2009-04-12 15:15 . 2009-01-07 18:14 60273 ----a-w c:\windows\system32\pthreadGC2.dll
2009-04-12 15:15 . 2009-04-12 15:15 -------- d-----w c:\documents and settings\OMAR\Local Settings\Application Data\Real
2009-04-12 15:15 . 2009-04-12 15:15 -------- d-----w c:\program files\K-Lite Codec Pack
2009-04-12 14:33 . 2009-04-12 14:33 -------- d-----w c:\documents and settings\OMAR\Application Data\DivX
2009-04-11 22:38 . 2004-08-03 21:56 363520 ----a-w c:\windows\system32\dllcache\psisdecd.dll
2009-04-11 22:38 . 2004-08-03 21:56 363520 ----a-w c:\windows\system32\psisdecd.dll
2009-04-11 11:23 . 2009-04-11 11:23 -------- d-----w c:\program files\ARAR
2009-04-10 20:06 . 2009-04-10 20:06 -------- d-----w c:\program files\Batch Watermark Creator
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-07 17:04 . 2009-04-26 12:05 32 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-07 17:04 . 2009-04-26 12:05 2184 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-03 04:25 . 2009-03-12 06:35 89048 ----a-w c:\documents and settings\OMAR\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-30 12:46 . 2009-03-11 14:41 98304 ----a-w c:\windows\DUMP8d23.tmp
2009-04-26 13:11 . 2008-01-29 14:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-04-26 09:42 . 2009-04-26 09:42 1788 ----a-w c:\windows\system32\PerfStringBackup.TMP
2009-04-12 14:35 . 2009-03-17 20:34 664 ----a-w c:\windows\system32\d3d9caps.dat
2009-04-06 20:51 . 2009-04-06 20:51 -------- d-----w c:\program files\TechSmith
2009-04-06 20:50 . 2009-04-06 20:50 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-03 21:29 . 2009-04-03 21:29 -------- d-----w c:\program files\BitComet
2009-04-03 10:33 . 2009-04-03 10:33 -------- d-----w c:\program files\Common Files\LogoManager
2009-04-03 10:33 . 2009-04-03 10:33 -------- d-----w c:\program files\MobiMB Mobile Media Browser
2009-03-31 10:30 . 2009-03-31 10:30 -------- d-----w c:\program files\Windows Media Components
2009-03-31 06:59 . 2009-03-31 06:59 -------- d-----w c:\program files\DiskTrix
2009-03-30 22:34 . 2009-03-30 22:34 -------- d-----w c:\program files\TeraCopy
2009-03-25 23:07 . 2009-03-25 23:07 -------- d-----w c:\program files\Common Files\Macrovision Shared
2009-03-25 23:07 . 2009-03-25 23:07 -------- d-----w c:\program files\Common Files\Intel
2009-03-25 23:05 . 2009-03-25 23:05 -------- d-----w c:\program files\Intel
2009-03-24 10:47 . 2009-03-24 10:47 -------- d-----w c:\program files\VideoLAN
2009-03-22 08:20 . 2009-03-22 08:20 -------- d-----w c:\program files\MemoBar
2009-03-22 08:20 . 2009-03-22 08:20 737280 ----a-w c:\windows\iun6002.exe
2009-03-21 19:31 . 2009-03-21 19:30 -------- d-----w c:\program files\XP Codec Pack
2009-03-20 11:34 . 2009-03-20 11:34 -------- d-----w c:\program files\UltraISO
2009-03-19 13:53 . 2009-03-19 13:53 -------- d-----w c:\program files\Webteh
2009-03-19 11:23 . 2009-03-19 11:24 29480 ----a-w c:\windows\system32\msxml3a.dll
2009-03-19 11:23 . 2009-03-16 20:41 353576 ----a-w c:\windows\system32\msvcr71.dll
2009-03-19 11:23 . 2009-03-16 20:41 505128 ----a-w c:\windows\system32\msvcp71.dll
2009-03-16 20:42 . 2009-03-16 20:42 344064 ----a-w c:\windows\system32\dkll.dll
2009-03-16 20:42 . 2009-03-11 16:13 196608 ----a-w c:\windows\system32\maag.dll
2009-03-16 20:42 . 2009-03-11 16:13 1212416 ----a-w c:\windows\system32\ckll.dll
2009-03-16 20:42 . 2009-03-11 16:13 1986560 ----a-w c:\windows\system32\akll.dll
2009-03-16 20:40 . 2009-03-16 20:40 -------- d-----w c:\program files\Ozone
2009-03-16 20:03 . 2009-03-16 20:03 -------- d-----w c:\program files\Nokia
2009-03-16 20:03 . 2009-03-16 20:03 -------- d-----w c:\program files\Common Files\PCSuite
2009-03-16 20:03 . 2009-03-16 20:03 -------- d-----w c:\program files\Common Files\Nokia
2009-03-15 10:58 . 2009-03-15 10:58 -------- d-----w c:\program files\Nitro PDF
2009-03-15 10:58 . 2009-03-15 10:58 -------- d-----w c:\program files\Common Files\Nitro PDF
2009-03-15 10:58 . 2009-03-15 10:58 -------- d-----w c:\program files\Common Files\BCL Technologies
2009-03-14 15:20 . 2009-03-14 15:20 -------- d-----w c:\program files\Messenger Plus! Live
2009-03-14 09:21 . 2009-03-14 09:21 2678 ----a-w c:\windows\java\Packages\Data\
05BDFRVZ.DAT
2009-03-14 09:21 . 2009-03-14 09:21 2678 ----a-w c:\windows\java\Packages\Data\YTNFDBVL.DAT
2009-03-14 09:21 . 2009-03-14 09:21 2678 ----a-w c:\windows\java\Packages\Data\P7JTJDR1.DAT
2009-03-14 09:21 . 2009-03-14 09:21 2678 ----a-w c:\windows\java\Packages\Data\OULNL3PF.DAT
2009-03-14 09:21 . 2009-03-14 09:21 2678 ----a-w c:\windows\java\Packages\Data\5RTV9VLV.DAT
2009-03-12 21:35 . 2009-03-12 21:35 -------- d-----w c:\program files\MSXML 4.0
2009-03-12 05:37 . 2009-03-12 05:37 2232 ----a-w c:\windows\java\Packages\Data\LF17LFFR.DAT
2009-03-12 05:37 . 2009-03-12 05:37 155995 ----a-w c:\windows\java\Packages\JBNJBH3D.ZIP
2009-03-11 19:28 . 2009-03-11 19:28 -------- d-----w c:\program files\Nero
2009-03-11 19:28 . 2009-03-11 19:28 -------- d-----w c:\program files\Common Files\Ahead
2009-03-11 18:42 . 2009-03-11 18:42 -------- d-----w c:\program files\Microsoft.NET
2009-03-11 18:42 . 2009-03-11 18:42 -------- d-----w c:\program files\Microsoft ActiveSync
2009-03-11 17:03 . 2009-03-11 17:03 -------- d-----w c:\program files\MSI
2009-03-11 16:51 . 2009-03-11 16:51 -------- d-----w c:\program files\Golden Al-Wafi Translator
2009-03-11 16:51 . 2009-03-11 16:51 172032 ------w c:\windows\Setup1.exe
2009-03-11 16:51 . 2009-03-11 16:51 73216 ----a-w c:\windows\ST6UNST.EXE
2009-03-11 16:39 . 2009-03-11 16:39 -------- d-----w c:\program files\GRETECH
2009-03-11 16:38 . 2009-03-11 16:38 -------- d-----w c:\program files\FLVPlayer
2009-03-11 16:38 . 2009-03-11 16:38 -------- d-----w c:\program files\Gabest
2009-03-11 16:09 . 2009-03-11 16:09 -------- d-----w c:\program files\Common Files\Real
2009-03-11 16:09 . 2009-03-11 16:09 -------- d-----w c:\program files\Real
2009-03-11 16:04 . 2009-03-11 16:04 -------- d-----w c:\program files\Windows Live SkyDrive
2009-03-11 16:03 . 2009-03-11 16:03 -------- d-----w c:\program files\Windows Live
2009-03-11 16:02 . 2009-03-11 16:02 -------- d-----w c:\program files\Microsoft
2009-03-11 15:42 . 2009-03-11 15:42 -------- d-----w c:\program files\Windows Media Connect 2
2009-03-11 15:34 . 2009-03-11 15:34 -------- d-----w c:\program files\Common Files\ACD Systems
2009-03-11 15:34 . 2009-03-11 15:34 -------- d-----w c:\program files\ACD Systems
2009-03-11 15:33 . 2009-03-11 15:33 10368 ----a-w c:\windows\system32\drivers\pfc.sys
2009-03-11 15:24 . 2009-03-11 15:24 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-11 15:24 . 2009-03-11 15:24 -------- d-----w c:\program files\Common Files\InstallShield
2009-03-11 15:24 . 2009-03-11 15:24 -------- d-----w c:\program files\SiS7012
2009-03-11 15:24 . 2009-03-11 15:24 -------- d-----w c:\program files\Gigabyte
2009-03-11 15:22 . 2009-03-11 15:22 -------- d-----w c:\program files\SiS Compatible VGA V2.07k
2009-03-11 15:16 . 2009-03-11 15:02 166455 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-11 15:04 . 2009-03-11 15:04 -------- d-----w c:\program files\microsoft frontpage
2009-03-11 15:03 . 2004-05-23 09:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-03-11 14:59 . 2009-03-11 14:59 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-06 14:44 . 2004-05-23 09:00 283648 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-05-23 09:00 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-05-23 09:00 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 10:20 . 2004-05-23 09:00 399360 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:19 . 2004-05-23 09:00 1846272 ----a-w c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-05-23 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-04-30 2799024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiS KHooker"="c:\windows\system32\khooker.exe" [2002-01-24 290816]
"SiSUSBRG"="c:\windows\sisUSBrg.exe" [2002-04-25 32768]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-04-26 206088]
"SMSERIAL"="sm56hlpr.exe" - c:\windows\sm56hlpr.exe [2005-06-06 544768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-05-23 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\MSI\Star Key Bluetooth Software\BTTray.exe [2005-5-31 577597]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-5-4 113664]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Snagit 9.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Snagit 9.lnk
backup=c:\windows\pss\Snagit 9.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"17871:TCP"= 17871:TCP:BitComet 17871 TCP
"17871:UDP"= 17871:UDP:BitComet 17871 UDP
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 05:29 م 33808]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [11/03/2009 07:20 م 332928]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [11/03/2009 06:24 م 177280]
S3 bepldr;BCL easyPDF SDK 5 Loader;c:\program files\Common Files\BCL Technologies\NitroPDF5\bepldr.exe [11/02/2008 11:58 ص 151552]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{db6da1d0-16cd-11de-a8b2-00c0ca220bbe}]
\Shell\AutoRun\command - husyu8n.exe
\Shell\open\Command - husyu8n.exe
.
Contents of the 'Scheduled Tasks' folder
2009-04-28 c:\windows\Tasks\DefragExpress.job
- c:\program files\DiskTrix\DefragExpress\DefragExpress.exe [2009-03-30 13:26]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\MSI\Star Key Bluetooth Software\btsendto_ie_ctx.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-07 20:06
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1988)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\TeraCopy\TeraCopyExt.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\MSI\STAR KEY BLUETOOTH SOFTWARE\BIN\BTWDINS.EXE
c:\program files\NERO\NERO 7\INCD\INCDSRV.EXE
.
**************************************************************************
.
Completion time: 2009-05-07 20:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-07 17:10
Pre-Run: 4,828,577,792 bytes free
Post-Run: 5,627,969,536 bytes free
245 --- E O F --- 2009-05-06 18:59