ComboFix 09-05-08.03 - USER 05/10/2009 0:03.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1256.971.1033.18.502.265 [GMT 4:00]
Running from: c:\documents and settings\USER\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
.
((((((((((((((((((((((((( Files Created from 2009-04-09 to 2009-05-09 )))))))))))))))))))))))))))))))
.
2009-05-09 19:47 . 2009-05-09 19:47 -------- d-----w c:\program files\Trend Micro
2009-04-24 21:03 . 2009-04-24 21:03 -------- d-----w c:\windows\Ela-Salaty
2009-04-24 21:03 . 2009-04-24 21:03 -------- d-----w c:\program files\Ela-Salaty
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-09 20:07 . 2009-01-27 14:49 7008544 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-09 20:07 . 2009-01-27 14:49 212000 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-08 20:30 . 2009-01-27 14:49 93668 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-08 20:30 . 2009-01-27 14:49 20420 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-03-15 17:35 . 2009-03-15 17:35 -------- d-----w c:\program files\Common Files\Labcenter Electronics
2009-03-15 17:34 . 2009-03-15 17:34 -------- d-----w c:\program files\Labcenter Electronics
2009-03-15 17:34 . 2008-08-30 09:26 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-15 16:35 . 2008-08-30 09:26 -------- d-----w c:\program files\Common Files\Adobe
2009-03-13 15:54 . 2008-08-30 09:09 83808 ----a-w c:\documents and settings\USER\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-13 13:23 . 2009-03-13 13:15 -------- d-----w c:\program files\Windows Live
2009-03-13 13:19 . 2009-03-13 13:19 -------- d-----w c:\program files\Microsoft Sync Framework
2009-03-13 13:18 . 2009-03-13 13:18 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-03-13 13:16 . 2009-03-13 13:16 -------- d-----w c:\program files\Microsoft
2009-03-13 13:16 . 2009-03-13 13:16 -------- d-----w c:\program files\Windows Live SkyDrive
2009-03-13 11:47 . 2009-03-13 11:47 -------- d-----w c:\program files\Common Files\Windows Live
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Creative Live! Cam Manager"="c:\program files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [2007-05-02 151552]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_05\bin\jusched.exe" [2005-08-26 36975]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2006-04-19 65536]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2006-05-04 86016]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-02 737369]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"V0470Mon.exe"="c:\windows\V0470Mon.exe" [2007-04-11 32768]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-09-30 185872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-04 110592]
"SMSERIAL"="sm56hlpr.exe" - c:\windows\sm56hlpr.exe [2006-01-20 544768]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-07-21 16261632]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\USER\Start Menu\Programs\Startup\
Ela-Salaty.lnk - c:\program files\Ela-Salaty\Salaty.exe [2007-3-5 5349888]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-8-30 113664]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-1-17 1748992]
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-8-30 278528]
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2003-8-6 51776]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 Hotkey;Hotkey;c:\windows\system32\drivers\HOTKEY.sys [30/08/2008 04:45 م 9867]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [14/01/2009 05:53 م 226656]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [04/04/2007 02:58 م 24344]
S1 mailKmd;mailKmd; [x]
S1 Wbutton;Wbutton;c:\windows\system32\drivers\Wbutton.sys --> c:\windows\system32\drivers\Wbutton.sys [?]
S3 VF0470Vid;Live! Cam Notebook (VF0470);c:\windows\system32\drivers\V0470Vid.sys [10/09/2008 12:48 ص 146368]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{95a830f6-1d46-11de-a30a-00130270108f}]
\Shell\AutoRun\command - d:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
\Shell\open\command - d:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
.
Contents of the 'Scheduled Tasks' folder
2009-01-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 10:21]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-LMgrVolOSD - c:\program files\Launch Manager\OSD.exe
HKLM-Run-LMgrOSD - c:\program files\Launch Manager\OSDCtrl.exe
HKLM-Run-CtrlVol - c:\program files\Launch Manager\CtrlVol.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.tvquran.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-10 00:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CtrlVol = c:\program files\Launch Manager\CtrlVol.exe?(???\??????|x??|????q??|?j?wQj?w????????,???
???????????????d??????|????????p?????@?.???????0y?w$??????????????sx??s@??????????????|h??st??????????s?????????????????C?sc"?sx??s???????w??@?N'?s?n??

??n?????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1560)
c:\windows\system32\klogon.dll
c:\windows\system32\igfxdev.dll
.
Completion time: 2009-05-09 0:08
ComboFix-quarantined-files.txt 2009-05-09 20:08
Pre-Run: 50,763,444,224 bytes free
Post-Run: 51,331,510,272 bytes free
128
*************************************************************
تفضل عزيزي