ComboFix 09-05-11.08 - Administrator 05/12/2009 14:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.965.1033.18.2047.1448 [GMT -7:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\artools.dll
c:\windows\system32\kakle.dll
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
c:\windows\system32\winitn.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Files Created from 2009-04-12 to 2009-05-12 )))))))))))))))))))))))))))))))
.
2009-05-12 20:28 . 2009-05-12 20:28 -------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-05-12 08:25 . 2009-05-12 08:25 -------- d-----w c:\program files\CCleaner
2009-05-12 07:54 . 2009-05-12 08:07 -------- d-----w c:\windows\system32\NtmsData
2009-05-10 02:44 . 2009-05-10 02:44 -------- d-----w c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-05-04 23:18 . 2009-05-04 23:19 -------- d-----w c:\documents and settings\Administrator\Application Data\GetRightToGo
2009-05-02 18:50 . 2009-05-02 18:50 -------- d-----w c:\documents and settings\Administrator\Application Data\MSNShell
2009-05-02 18:50 . 2009-05-02 19:21 -------- d-----w c:\program files\MSNShell
2009-05-01 19:02 . 2009-05-01 19:02 -------- d--h--w c:\windows\PIF
2009-04-25 04:59 . 2009-04-25 04:59 -------- d-----w c:\documents and settings\Administrator\Application Data\PCF-VLC
2009-04-25 00:43 . 2009-05-10 02:43 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Ashampoo
2009-04-25 00:21 . 2009-05-01 05:01 -------- d-----w c:\documents and settings\Administrator\Application Data\IDM
2009-04-25 00:21 . 2009-05-01 18:59 -------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2009-04-25 00:17 . 2009-05-01 19:00 -------- d-----w c:\program files\Internet Download Manager
2009-04-22 12:12 . 2009-04-22 12:12 203776 ----a-w c:\windows\system32\clrviddc.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-12 21:55 . 2009-03-29 19:27 589856 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-12 21:55 . 2009-03-29 19:27 4144 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-12 21:54 . 2009-03-18 19:07 -------- d-----w c:\program files\Common Files\Akamai
2009-05-12 21:53 . 2009-03-29 19:27 3558944 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-12 21:53 . 2009-03-29 19:27 29932 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-12 18:56 . 2009-03-28 11:43 -------- d-----w c:\program files\Real_SC
2009-05-12 12:35 . 2009-03-10 19:01 -------- d-----w c:\program files\Registry Genius
2009-05-10 02:11 . 2009-03-10 19:12 -------- d-----w c:\program files\Ahead
2009-05-04 23:40 . 2009-03-10 18:58 -------- d-----w c:\program files\Wave Splitter
2009-04-30 14:36 . 2009-03-10 18:48 -------- d-----w c:\program files\aseel
2009-04-25 00:23 . 2009-03-10 18:09 293400 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-25 00:19 . 2009-03-10 18:53 344064 ----a-w c:\windows\system32\dkll.dll
2009-04-25 00:19 . 2009-03-10 18:53 196608 ----a-w c:\windows\system32\maag.dll
2009-04-25 00:19 . 2009-03-10 18:53 1212416 ----a-w c:\windows\system32\ckll.dll
2009-04-25 00:19 . 2009-03-10 18:53 1986560 ----a-w c:\windows\system32\akll.dll
2009-03-30 11:21 . 2009-03-10 18:51 -------- d-----w c:\program files\Total Video Converter
2009-03-29 19:54 . 2008-01-30 02:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-03-29 19:54 . 2009-03-29 19:28 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-03-29 19:54 . 2009-03-29 19:28 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-03-29 19:27 . 2009-03-29 19:27 -------- d-----w c:\program files\Kaspersky Lab
2009-03-28 03:23 . 2009-03-28 03:23 -------- d-----w c:\program files\MSSOAP
2009-03-28 03:00 . 2009-03-28 03:00 164 ----a-w c:\windows\install.dat
2009-03-26 21:40 . 2009-03-10 19:17 -------- d-----w c:\program files\JetAudio
2009-03-25 06:18 . 2009-03-25 06:18 -------- d-----w c:\program files\MSN Messenger
2009-03-25 04:36 . 2009-03-25 04:36 16 ----a-w c:\windows\system32\DataRnvx.dat
2009-03-25 04:00 . 2009-03-25 03:57 -------- d-----w c:\program files\Your Uninstaller 2008
2009-03-23 23:04 . 2009-03-23 23:01 68508 ----a-w c:\windows\hpoins05.dat
2009-03-22 01:29 . 2009-03-22 01:29 -------- d-----w c:\program files\Common Files\xing shared
2009-03-22 01:29 . 2009-03-10 18:50 -------- d-----w c:\program files\Common Files\Real
2009-03-22 01:28 . 2003-03-19 04:14 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-03-18 19:54 . 2009-03-18 19:54 56 ---ha-w c:\windows\system32\ezsidmv.dat
2009-03-18 19:06 . 2009-03-18 19:06 -------- d-----w c:\program files\Metacafe
2009-03-10 19:28 . 2009-03-10 19:28 136 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2009-03-10 19:21 . 2009-03-10 19:21 603904 ----a-w c:\windows\system32\TUProgSt.exe
2009-03-10 19:21 . 2009-03-10 19:21 362240 ----a-w c:\windows\system32\TuneUpDefragService.exe
2009-03-10 19:16 . 2003-02-21 12:42 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-03-10 19:06 . 2009-03-10 19:06 2232 ----a-w c:\windows\java\Packages\Data\V17HJP7T.DAT
2009-03-10 19:06 . 2009-03-10 19:06 155995 ----a-w c:\windows\java\Packages\MIE657HV.ZIP
2009-03-10 19:06 . 2009-03-10 19:06 2678 ----a-w c:\windows\java\Packages\Data\BJVN3P3F.DAT
2009-03-10 19:06 . 2009-03-10 19:06 2678 ----a-w c:\windows\java\Packages\Data\6T7DVXR9.DAT
2009-03-10 19:06 . 2009-03-10 19:06 2678 ----a-w c:\windows\java\Packages\Data\
0LVDZPBF.DAT
2009-03-10 19:06 . 2009-03-10 19:06 2678 ----a-w c:\windows\java\Packages\Data\
041FNJXF.DAT
2009-03-10 19:06 . 2009-03-10 19:06 2678 ----a-w c:\windows\java\Packages\Data\WN7D7DN9.DAT
2009-03-10 18:43 . 2009-03-10 18:43 40960 ----a-w c:\windows\system32\SSubTmr6.dll
2009-03-10 18:11 . 2009-03-10 17:47 166455 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-10 18:02 . 2009-03-10 18:03 32768 ------w c:\windows\system32\MWLPS.dll
2009-03-10 17:47 . 2008-04-14 12:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-03-10 17:44 . 2009-03-10 17:44 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-03 10:38 . 2009-03-03 10:38 128840 ----a-w c:\windows\system32\Metacafe.scr
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-03-29 206088]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-03-10 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-22 198160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Metacafe.lnk]
backup=c:\windows\pss\Metacafe.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acer WLAN 11g USB Dongle.lnk]
backup=c:\windows\pss\Acer WLAN 11g USB Dongle.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Metacafe.lnk]
backup=c:\windows\pss\Metacafe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\'Ashampoo AntiSpyWare 2 Guard'
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxMoniter
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\program files\BBC Arabic\bbcarabic.exe"= c:\program files\BBC Arabic\bbcarabic.exe
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1989:TCP"= 1989:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
"1093:TCP"= 1093:TCP:Akamai NetSession Interface
"1434:TCP"= 1434:TCP:Akamai NetSession Interface
"1145:TCP"= 1145:TCP:Akamai NetSession Interface
"3683:TCP"= 3683:TCP:Akamai NetSession Interface
"2425:TCP"= 2425:TCP:Akamai NetSession Interface
"1618:TCP"= 1618:TCP:Akamai NetSession Interface
"1775:TCP"= 1775:TCP:Akamai NetSession Interface
"3266:TCP"= 3266:TCP:Akamai NetSession Interface
"1057:TCP"= 1057:TCP:Akamai NetSession Interface
"4631:TCP"= 4631:TCP:Akamai NetSession Interface
"4655:TCP"= 4655:TCP:Akamai NetSession Interface
"1078:TCP"= 1078:TCP:Akamai NetSession Interface
"1055:TCP"= 1055:TCP:Akamai NetSession Interface
"1763:TCP"= 1763:TCP:Akamai NetSession Interface
"1061:TCP"= 1061:TCP:Akamai NetSession Interface
"2129:TCP"= 2129:TCP:Akamai NetSession Interface
"2233:TCP"= 2233:TCP:Akamai NetSession Interface
"1059:TCP"= 1059:TCP:Akamai NetSession Interface
"1069:TCP"= 1069:TCP:Akamai NetSession Interface
"1088:TCP"= 1088:TCP:Akamai NetSession Interface
"1360:TCP"= 1360:TCP:Akamai NetSession Interface
"1378:TCP"= 1378:TCP:Akamai NetSession Interface
"1080:TCP"= 1080:TCP:Akamai NetSession Interface
"1081:TCP"= 1081:TCP:Akamai NetSession Interface
"1071:TCP"= 1071:TCP:Akamai NetSession Interface
"1052:TCP"= 1052:TCP:Akamai NetSession Interface
"1060:TCP"= 1060:TCP:Akamai NetSession Interface
"1087:TCP"= 1087:TCP:Akamai NetSession Interface
"1062:TCP"= 1062:TCP:Akamai NetSession Interface
"1580:TCP"= 1580:TCP:Akamai NetSession Interface
"1927:TCP"= 1927:TCP:Akamai NetSession Interface
"1058:TCP"= 1058:TCP:Akamai NetSession Interface
"1067:TCP"= 1067:TCP:Akamai NetSession Interface
"4415:TCP"= 4415:TCP:Akamai NetSession Interface
"1396:TCP"= 1396:TCP:Akamai NetSession Interface
"1068:TCP"= 1068:TCP:Akamai NetSession Interface
"1383:TCP"= 1383:TCP:Akamai NetSession Interface
"1064:TCP"= 1064:TCP:Akamai NetSession Interface
"1147:TCP"= 1147:TCP:Akamai NetSession Interface
"1063:TCP"= 1063:TCP:Akamai NetSession Interface
"1083:TCP"= 1083:TCP:Akamai NetSession Interface
"1077:TCP"= 1077:TCP:Akamai NetSession Interface
"1074:TCP"= 1074:TCP:Akamai NetSession Interface
"1066:TCP"= 1066:TCP:Akamai NetSession Interface
"1166:TCP"= 1166:TCP:Akamai NetSession Interface
"4266:TCP"= 4266:TCP:Akamai NetSession Interface
"1072:TCP"= 1072:TCP:Akamai NetSession Interface
"2772:TCP"= 2772:TCP:Akamai NetSession Interface
"2651:TCP"= 2651:TCP:Akamai NetSession Interface
"1318:TCP"= 1318:TCP:Akamai NetSession Interface
"1065:TCP"= 1065:TCP:Akamai NetSession Interface
"1971:TCP"= 1971:TCP:Akamai NetSession Interface
"1051:TCP"= 1051:TCP:Akamai NetSession Interface
"1082:TCP"= 1082:TCP:Akamai NetSession Interface
"1334:TCP"= 1334:TCP:Akamai NetSession Interface
"1054:TCP"= 1054:TCP:Akamai NetSession Interface
"1292:TCP"= 1292:TCP:Akamai NetSession Interface
"1931:TCP"= 1931:TCP:Akamai NetSession Interface
"1086:TCP"= 1086:TCP:Akamai NetSession Interface
"1168:TCP"= 1168:TCP:Akamai NetSession Interface
"1953:TCP"= 1953:TCP:Akamai NetSession Interface
"1049:TCP"= 1049:TCP:Akamai NetSession Interface
"1053:TCP"= 1053:TCP:Akamai NetSession Interface
"1056:TCP"= 1056:TCP:Akamai NetSession Interface
"1478:TCP"= 1478:TCP:Akamai NetSession Interface
"1161:TCP"= 1161:TCP:Akamai NetSession Interface
"2601:TCP"= 2601:TCP:Akamai NetSession Interface
"2650:TCP"= 2650:TCP:Akamai NetSession Interface
"2739:TCP"= 2739:TCP:Akamai NetSession Interface
"4079:TCP"= 4079:TCP:Akamai NetSession Interface
"4026:TCP"= 4026:TCP:Akamai NetSession Interface
"1079:TCP"= 1079:TCP:Akamai NetSession Interface
"1075:TCP"= 1075:TCP:Akamai NetSession Interface
"1050:TCP"= 1050:TCP:Akamai NetSession Interface
"1925:TCP"= 1925:TCP:Akamai NetSession Interface
"1085:TCP"= 1085:TCP:Akamai NetSession Interface
"1092:TCP"= 1092:TCP:Akamai NetSession Interface
"1073:TCP"= 1073:TCP:Akamai NetSession Interface
"1960:TCP"= 1960:TCP:Akamai NetSession Interface
"1070:TCP"= 1070:TCP:Akamai NetSession Interface
"3148:TCP"= 3148:TCP:Akamai NetSession Interface
"1090:TCP"= 1090:TCP:Akamai NetSession Interface
"4617:TCP"= 4617:TCP:Akamai NetSession Interface
"1999:TCP"= 1999:TCP:Akamai NetSession Interface
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [1/29/2008 7:29 PM 33808]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [4/14/2008 5:00 AM 14336]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [1/14/2009 6:53 PM 226656]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [3/10/2009 12:21 PM 603904]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [3/13/2008 8:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [4/30/2008 7:06 PM 24592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0dc862b5-0daa-11de-9512-0019215cb2a3}]
\Shell\AutoRun\command - J:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0dc862ba-0daa-11de-9512-0019215cb2a3}]
\Shell\AutoRun\command - J:\AutoRun.exe
.
Contents of the 'Scheduled Tasks' folder
2009-05-12 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-21 00:28]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.kw/
IE: Download all links with IDM
IE: Download FLV video content with IDM
IE: Download with IDM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-12 14:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):f2,1b,67,4c,7f,dc,f9,cc,b3,99,10,85,73,2e,b0,92,a2,83,f1,56,08,
64,39,54,7c,77,08,fd,78,06,1b,6e,f4,74,c7,79,45,a1,bd,1a,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{abf8cb13-fc61-43ca-a4bd-9db9999e9125}]
@Denied: (Full) (Everyone)
"Model"=dword:00000078
"Therad"=dword:00000002
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1368)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1796)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\HPZipm12.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-12 14:57 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-12 21:57
Pre-Run: 184,245,780,480 bytes free
Post-Run: 184,429,613,056 bytes free
292