الله يبارك فيك
وجازي ربي الف الف خير
والله يدخلك الجنة ( أمين )
combofix 09-05-07.a0 - damry-pc 05/08/2009 14:51.1 - ntfsx86
microsoft windows xp professional 5.1.2600.3.1256.966.1025.18.2047.1557 [gmt 3:00]
running from: C:\documents and settings\damry-pc\my documents\combofix.exe
av: Kaspersky internet security *on-access scanning disabled* (updated)
fw: Kaspersky internet security *disabled*
warning -this machine does not have the recovery console installed !!
.
((((((((((((((((((((((((((((((((((((((( other deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\hkn6k.bat
c:\windows\artools.dll
c:\windows\system32\kakle.dll
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\nmdfgds1.dll
c:\windows\system32\olhrwef.exe
c:\windows\system32\winitn.dll
d:\autorun.inf
d:\hkn6k.bat
e:\autorun.inf
e:\hkn6k.bat
.
((((((((((((((((((((((((( files created from 2009-04-08 to 2009-05-08 )))))))))))))))))))))))))))))))
.
2009-05-08 07:03 . 2009-05-08 07:03 -------- d-----w c:\windows\sun
2009-05-08 07:02 . 2009-05-08 07:02 -------- d-----w c:\program files\the kmplayer
2009-05-08 06:43 . 2008-06-14 17:31 271616 -c----w c:\windows\system32\dllcache\bthport.sys
2009-05-08 06:43 . 2008-06-14 17:31 271616 ------w c:\windows\system32\drivers\bthport.sys
2009-05-08 06:43 . 2009-05-08 06:48 -------- d-----w c:\program files\windows live safety center
2009-05-08 06:41 . 2009-02-09 11:22 2190592 -c----w c:\windows\system32\dllcache\ntoskrnl.exe
2009-05-08 06:41 . 2009-02-09 11:22 2146816 -c----w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-05-08 06:41 . 2009-02-09 11:22 2025472 -c----w c:\windows\system32\dllcache\ntkrpamp.exe
2009-05-08 06:40 . 2008-10-24 11:21 455296 -c----w c:\windows\system32\dllcache\mrxsmb.sys
2009-05-08 06:37 . 2009-05-08 06:37 -------- d-----w c:\program files\microsoft windows onecare live
2009-05-08 06:32 . 2009-05-08 10:50 -------- d--h--w c:\windows\$hf_mig$
2009-05-08 06:19 . 2009-05-08 06:19 -------- d-----w c:\windows\atk0100
2009-05-08 06:15 . 2004-04-28 12:05 5786 ----a-w c:\windows\system32\drivers\atkacpi.sys
2009-05-08 05:33 . 2009-05-08 06:29 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-05-08 05:33 . 2009-05-08 06:29 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-05-08 05:33 . 2009-05-08 11:54 774176 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-08 05:33 . 2009-05-08 11:53 221216 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-08 05:33 . 2009-05-08 11:54 -------- d-----w c:\documents and settings\all users\application data\kaspersky lab
2009-05-08 05:16 . 2009-05-08 05:16 -------- d-----w c:\program files\multimedia card reader
2009-05-08 05:14 . 2009-05-08 05:14 -------- d-----w c:\documents and settings\damry-pc\application data\asus security protect manager
2009-05-08 04:42 . 2009-05-08 05:39 -------- d-----w c:\program files\kaspersky lab
2009-05-08 04:41 . 2009-05-08 04:41 -------- d-----w c:\documents and settings\all users\application data\kaspersky lab setup files
2009-05-08 04:38 . 2009-05-08 04:38 -------- d-----w c:\documents and settings\damry-pc\contacts
2009-05-08 04:37 . 2009-05-08 04:37 -------- d-----w c:\program files\messenger plus! Live
2009-05-08 04:29 . 2009-05-08 04:29 -------- d-----w c:\documents and settings\damry-pc\application data\desktopicon
2009-05-08 04:29 . 2009-05-08 04:29 -------- d-----w c:\program files\formatfactory
2009-05-08 04:26 . 2009-05-08 04:26 -------- d-----w c:\program files\windows live
2009-05-08 04:24 . 2009-05-08 04:24 -------- d-----w c:\program files\java
2009-05-08 04:24 . 2009-05-08 04:24 -------- d-----w c:\program files\common files\java
2009-05-08 04:07 . 2009-05-08 04:07 -------- d-----w c:\program files\common files\xing shared
2009-05-08 04:07 . 2009-05-08 04:07 -------- d-----w c:\documents and settings\damry-pc\application data\nokia
2009-05-08 04:07 . 2009-05-08 04:07 -------- d-----w c:\documents and settings\damry-pc\application data\pc suite
2009-05-08 04:07 . 2009-05-08 04:07 -------- d-----w c:\documents and settings\all users\application data\pc suite
2009-05-08 04:07 . 2009-05-08 04:07 -------- d-----w c:\program files\common files\real
2009-05-08 04:06 . 2009-05-08 04:06 -------- d-----w c:\program files\camstudio
2009-05-08 04:06 . 2009-05-08 04:06 -------- d-----w c:\program files\real
2009-05-08 04:03 . 2009-05-08 04:10 196608 ----a-w c:\windows\system32\maag.dll
2009-05-08 04:02 . 2009-05-08 04:02 -------- d-----w c:\documents and settings\all users\application data\installations
.
(((((((((((((((((((((((((((((((((((((((( find3m report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-08 11:54 . 2009-05-08 05:33 9224 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-08 11:53 . 2009-05-08 05:33 3932 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-08 11:18 . 2008-04-15 12:00 58920 ----a-w c:\windows\system32\perfc001.dat
2009-05-08 11:18 . 2008-04-15 12:00 328690 ----a-w c:\windows\system32\perfh001.dat
2009-05-08 06:29 . 2008-01-29 15:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-05-08 04:08 . 2009-05-08 02:00 -------- d-----w c:\program files\internet download manager
2009-05-08 04:07 . 2003-03-18 17:14 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-05-08 04:07 . 2003-02-21 01:42 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-05-08 04:05 . 2009-05-08 04:05 -------- d-----w c:\program files\common files\pcsuite
2009-05-08 04:05 . 2009-05-08 04:05 -------- d-----w c:\program files\common files\nokia
2009-05-08 04:05 . 2009-05-08 04:03 -------- d-----w c:\program files\nokia
2009-05-08 04:05 . 2009-05-08 04:05 -------- d-----w c:\program files\difx
2009-05-08 04:05 . 2009-05-08 04:05 -------- d-----w c:\program files\pc connectivity solution
2009-05-08 04:05 . 2009-05-08 04:05 13824 ----a-w c:\windows\system32\drivers\splitcam.sys
2009-05-08 04:04 . 2009-05-08 04:04 -------- d-----w c:\program files\teamviewer
2009-05-08 04:03 . 2009-05-08 04:03 -------- d-----w c:\program files\splitcam
2009-05-08 04:03 . 2009-05-08 02:33 -------- d--h--w c:\program files\installshield installation information
2009-05-08 04:03 . 2009-05-08 04:03 -------- d-----w c:\program files\real_sc
2009-05-08 03:28 . 2009-05-08 03:28 27264 ----a-w c:\documents and settings\damry-pc\local settings\application data\gdipfontcachev1.dat
2009-05-08 03:27 . 2009-05-08 03:27 0 ----a-w c:\windows\ativpsrm.bin
2009-05-08 03:26 . 2009-05-08 03:22 -------- d-----w c:\program files\ati technologies
2009-05-08 03:22 . 2009-05-08 02:33 -------- d-----w c:\program files\common files\installshield
2009-05-08 03:21 . 2009-05-08 03:21 -------- d-----w c:\program files\widcomm
2009-05-08 03:17 . 2009-05-08 03:17 -------- d-----w c:\program files\asus security center
2009-05-08 03:17 . 2009-05-08 03:17 -------- d-----w c:\program files\fingerprint sensor
2009-05-08 02:33 . 2009-05-08 02:33 -------- d-----w c:\program files\realtek
2009-05-08 02:15 . 2009-05-08 01:38 -------- d-----w c:\program files\intel
2009-05-08 01:38 . 2009-05-08 01:38 -------- d-----w c:\program files\common files\intel
2009-05-08 01:37 . 2009-05-08 01:08 86327 ----a-w c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-05-08 01:09 . 2009-05-08 01:09 -------- d-----w c:\program files\microsoft frontpage
2009-05-08 01:08 . 2008-04-15 12:00 67 --sha-w c:\windows\fonts\desktop.ini
2009-05-08 01:05 . 2009-05-08 01:05 22144 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-26 15:35 . 2009-05-07 07:42 210352 ----a-w c:\windows\system32\idmmbc.dll
2009-03-08 01:34 . 2008-04-15 12:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 01:34 . 2008-04-15 12:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 01:33 . 2008-04-15 12:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 01:33 . 2008-04-15 12:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 01:32 . 2008-04-15 12:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 01:32 . 2008-04-15 12:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 01:31 . 2008-04-15 12:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 01:31 . 2008-04-15 12:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 01:31 . 2008-04-15 12:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 01:22 . 2008-04-15 12:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:20 . 2008-04-15 12:00 283136 ----a-w c:\windows\system32\pdh.dll
2009-02-13 13:59 . 2009-05-08 02:33 17508864 ----a-w c:\windows\rthdcpl.exe
2009-02-13 13:49 . 2009-05-08 02:33 5029376 ----a-w c:\windows\system32\drivers\rtkhdaud.sys
2009-02-09 14:04 . 2008-04-15 12:00 1846656 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:34 . 2009-05-08 02:33 35840 ----a-w c:\windows\system32\rtkcoinstxp.dll
2009-02-09 11:22 . 2008-04-14 21:12 2025472 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:22 . 2008-04-15 12:00 2146816 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:21 . 2008-04-15 12:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-09 10:51 . 2008-04-15 12:00 723456 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:51 . 2008-04-15 12:00 681472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:51 . 2008-04-15 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:51 . 2008-04-15 12:00 693760 ----a-w c:\windows\system32\ntdll.dll
.
((((((((((((((((((((((((((((((((((((( reg loading points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*note* empty entries & legit default entries are not shown
regedit4
[hkey_current_user\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\run]
"intelzeroconfig"="c:\program files\intel\wifi\bin\zcfgsvc.exe" [2008-10-16 1368064]
"intelwireless"="c:\program files\common files\intel\wirelesscommon\ifrmewrk.exe" [2008-10-16 1191936]
"cognizancets"="c:\progra~1\asusse~1\asusse~1\bin\astsvcc.dll" [2003-12-22 17920]
"startccc"="c:\program files\ati technologies\ati.ace\core-static\clistart.exe" [2008-08-29 61440]
"tkbellexe"="c:\program files\common files\real\update_ob\realsched.exe" [2009-05-08 185896]
"sunjavaupdatesched"="c:\program files\java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"avp"="c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe" [2009-05-08 201992]
"hcontrol"="c:\windows\atk0100\hcontrol.exe" [2004-04-28 69632]
"rthdcpl"="rthdcpl.exe" - c:\windows\rthdcpl.exe [2009-02-13 17508864]
[hkey_users\.default\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
c:\documents and settings\all users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
bluetooth.lnk - c:\program files\widcomm\bluetooth software\bttray.exe [2008-4-14 596584]
[hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon\notify\onecard]
2007-02-06 22:30 74240 ----a-r c:\program files\asus security center\asus security protect manager\bin\aswlnpkg.dll
[hkey_local_machine\system\currentcontrolset\control\lsa]
notification packages reg_multi_sz scecli aswlnpkg
[hkey_local_machine\software\microsoft\security center\monitoring\kasperskyantivirus]
"disablemonitoring"=dword:00000001
[hklm\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"enablefirewall"= 0 (0x0)
[hklm\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\network diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\program files\\teamviewer\\version4\\teamviewer.exe"=
"c:\\program files\\windows live\\messenger\\msnmsgr.exe"=
"c:\\program files\\windows live\\messenger\\livecall.exe"=
"c:\\documents and settings\\all users\\application data\\kaspersky lab setup files\\kaspersky internet security 2009\\english\\setup.exe"=
r0 klbg;kaspersky lab boot guard driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 06:29 م 33808]
r2 asbroker;logon session broker;c:\windows\system32\svchost.exe -k cognizance [15/04/2008 03:00 م 14336]
r2 aschannel;local communication channel;c:\windows\system32\svchost.exe -k cognizance [15/04/2008 03:00 م 14336]
r3 atihdmiservice;ati function driver for hdmi service;c:\windows\system32\drivers\atihdmi.sys [08/05/2009 06:22 ص 93184]
r3 atkxpdisplayname;atkxpdisplayname;c:\windows\system32\drivers\atkacpi.sys [08/05/2009 09:15 ص 5786]
r3 klfltdev;kaspersky lab klfltdev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 07:02 م 26640]
s3 ambfilt;ambfilt;c:\windows\system32\drivers\ambfilt.sys [08/05/2009 05:33 ص 1684736]
s3 avpsys;avpsys;\??\c:\windows\system32\drivers\cdaudio.sys --> c:\windows\system32\drivers\cdaudio.sys [?]
s3 klim5;kaspersky anti-virus ndis filter;c:\windows\system32\drivers\klim5.sys --> c:\windows\system32\drivers\klim5.sys [?]
[hkey_local_machine\software\microsoft\windows nt\currentversion\svchost]
cognizance reg_multi_sz asbroker aschannel
[hkey_local_machine\software\microsoft\active setup\installed components\>{60b49e34-c7cc-11d0-8953-00a0c90347ff}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",brandieactivesetup signup
.
Contents of the 'scheduled tasks' folder
2009-05-08 c:\windows\tasks\user_feed_synchronization-{d41e619b-c61e-43c6-9a45-67680e9ac16b}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 01:31]
.
- - - - orphans removed - - - -
hkcu-run-cdoosoft - c:\windows\system32\olhrwef.exe
.
------- supplementary scan -------
.
Ustart page = hxxp://www.google.com.sa/
ie: إرسال إلى &جهاز bluetooth... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
ie: إرسال إلى bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
ie: تحميل الكل بواسطة internet download manager - c:\program files\internet download manager\iegetall.htm
ie: تحميل بواسطة internet download manager - c:\program files\internet download manager\ieext.htm
ie: تحميل محتوى flv بواسطة internet download manager - c:\program files\internet download manager\iegetvl.htm
.
**************************************************************************
catchme 0.3.1398 w2k/xp/vista - rootkit/stealth malware detector by gmer,
rootkit scan 2009-05-08 14:55
windows 5.1.2600 service pack 3 ntfs
scanning hidden processes ...
Scanning hidden autostart entries ...
Scanning hidden files ...
Scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- dlls loaded under running processes ---------------------
- - - - - - - > 'winlogon.exe'(952)
c:\windows\system32\ati2evxx.dll
c:\windows\system32\klogon.dll
c:\program files\asus security center\asus security protect manager\bin\aswlnpkg.dll
c:\program files\asus security center\asus security protect manager\bin\itmsg.dll
c:\program files\asus security center\asus security protect manager\bin\trayicon.dll
c:\program files\asus security center\asus security protect manager\bin\brand.dll
c:\program files\asus security center\asus security protect manager\bin\aschnl.dll
c:\program files\asus security center\asus security protect manager\bin\itdac.dll
c:\program files\asus security center\asus security protect manager\bin\itreports.dll
c:\program files\asus security center\asus security protect manager\bin\bioauth.dll
c:\program files\asus security center\asus security protect manager\bin\asbioat.dll
c:\program files\asus security center\asus security protect manager\bin\itvcclient.dll
c:\program files\asus security center\asus security protect manager\bin\authwiz.dll
- - - - - - - > 'lsass.exe'(1008)
c:\program files\asus security center\asus security protect manager\bin\aswlnpkg.dll
c:\program files\asus security center\asus security protect manager\bin\itmsg.dll
- - - - - - - > 'explorer.exe'(3088)
c:\windows\system32\apshook.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\ieframe.dll
.
------------------------ other running processes ------------------------
.
C:\windows\system32\ati2evxx.exe
c:\program files\widcomm\bluetooth software\bin\btwdins.exe
c:\program files\intel\wifi\bin\s24evmon.exe
c:\windows\system32\ati2evxx.exe
c:\program files\intel\wifi\bin\evteng.exe
c:\program files\common files\intel\wirelesscommon\regsrvc.exe
c:\program files\asus security center\asus security protect manager\bin\asghost.exe
c:\windows\system32\scardsvr.exe
c:\program files\ati technologies\ati.ace\core-static\mom.exe
c:\program files\ati technologies\ati.ace\core-static\ccc.exe
c:\program files\widcomm\bluetooth software\btstackserver.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\atk0100\atkosd.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-08 14:56 - machine was rebooted
combofix-quarantined-files.txt 2009-05-08 11:56
pre-run: 33,356,566,528 bytes free
post-run: 33,425,330,176 bytes free
245 --- e o f --- 2009-05-08 10:50