ComboFix 09-05-16.03 - king 05/17/2009 0:15.10 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1256.966.1025.18.2046.1292 [GMT 3:00]
Running from: c:\users\king\Documents\Downloads\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Kaspersky Internet Security *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-04-16 to 2009-05-16 )))))))))))))))))))))))))))))))
.
2009-05-16 21:20 . 2009-05-16 21:20 -------- d-sh--w C:\$RECYCLE.BIN
2009-05-16 21:20 . 2009-05-16 21:20 17408 ----a-w c:\windows\system32\rpcnetp.exe
2009-05-16 21:05 . 2009-05-16 21:05 -------- d-----w c:\program files\XP TCPIP Repair
2009-05-16 20:25 . 2009-05-16 20:25 -------- d-----w C:\VundoFix Backups
2009-05-16 18:38 . 2009-05-16 21:20 17408 ----a-w c:\windows\system32\rpcnetp.dll
2009-05-01 02:00 . 2009-05-15 21:44 -------- d-----w c:\users\king\Contacts
2009-04-26 03:27 . 2009-04-26 03:27 -------- d-----w c:\program files\Ask Search Assistant
2009-04-21 09:17 . 2009-04-21 09:17 -------- d-----w c:\program files\CodeStuff
2009-04-17 10:23 . 2008-06-06 03:27 562176 ----a-w c:\windows\system32\msdtcprx.dll
2009-04-17 10:23 . 2008-06-06 03:27 38912 ----a-w c:\windows\system32\xolehlp.dll
2009-04-17 10:22 . 2009-03-03 04:39 551424 ----a-w c:\windows\system32\rpcss.dll
2009-04-17 10:22 . 2009-03-03 04:46 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-04-17 10:22 . 2009-03-03 04:46 3547632 ----a-w c:\windows\system32\ntoskrnl.exe
2009-04-17 10:22 . 2009-03-03 03:04 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-04-17 10:22 . 2009-03-03 04:39 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-04-17 10:22 . 2009-03-03 04:39 183296 ----a-w c:\windows\system32\sdohlp.dll
2009-04-17 10:22 . 2009-03-03 04:37 44032 ----a-w c:\windows\system32\iasdatastore.dll
2009-04-17 10:22 . 2009-03-03 04:37 98304 ----a-w c:\windows\system32\iasrecst.dll
2009-04-17 10:22 . 2009-03-03 04:37 54784 ----a-w c:\windows\system32\iasads.dll
2009-04-17 10:22 . 2009-03-03 02:38 17408 ----a-w c:\windows\system32\iashost.exe
2009-04-17 10:19 . 2008-12-06 04:42 376832 ----a-w c:\windows\system32\winhttp.dll
2009-04-17 10:18 . 2009-02-13 08:49 1255936 ----a-w c:\windows\system32\lsasrv.dll
2009-04-17 10:18 . 2009-02-13 08:49 72704 ----a-w c:\windows\system32\secur32.dll
2009-04-17 10:18 . 2009-03-17 03:38 13824 ----a-w c:\windows\system32\apilogen.dll
2009-04-17 10:18 . 2009-03-17 03:38 24064 ----a-w c:\windows\system32\amxread.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-16 21:19 . 2009-02-20 00:46 565280 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-16 21:19 . 2009-02-20 00:46 4060 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-16 21:19 . 2009-02-20 00:46 3168288 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-16 21:19 . 2009-02-20 00:46 26880 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-16 21:03 . 2006-11-02 12:50 174 --sha-w c:\program files\desktop.ini
2009-05-16 20:54 . 2008-12-12 15:24 44544 ----a-w c:\windows\system32\agremove.exe
2009-05-16 19:42 . 2009-02-01 23:44 691 ----a-w c:\users\king\AppData\Roaming\GetValue.vbs
2009-05-16 19:42 . 2009-02-01 23:44 35 ----a-w c:\users\king\AppData\Roaming\SetValue.bat
2009-05-16 18:38 . 2008-10-25 12:27 6944 ----a-w c:\users\king\AppData\Local\d3d9caps.dat
2009-05-14 00:00 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-05-01 00:25 . 2008-10-18 13:35 61536 ----a-w c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2009-04-26 03:27 . 2008-10-19 05:35 -------- d-----w c:\program files\Messenger Plus! Live
2009-04-16 08:59 . 2006-11-02 12:37 -------- d-----w c:\program files\Windows Defender
2009-04-16 08:58 . 2006-11-02 12:37 -------- d-----w c:\program files\Windows Journal
2009-04-16 08:58 . 2006-11-02 12:37 -------- d-----w c:\program files\Windows Collaboration
2009-04-16 08:58 . 2006-11-02 12:37 -------- d-----w c:\program files\Windows Calendar
2009-04-16 08:57 . 2006-11-02 12:37 -------- d-----w c:\program files\Windows Photo Gallery
2009-04-16 08:57 . 2006-11-02 12:37 -------- d-----w c:\program files\Windows Sidebar
2009-04-14 00:23 . 2009-04-13 01:51 90112 ----a-w c:\windows\system32\agsaami.dll
2009-04-14 00:23 . 2009-04-13 01:51 610304 ----a-w c:\windows\system32\agsaamg.dll
2009-04-14 00:23 . 2009-04-13 01:51 372736 ----a-w c:\windows\system32\agsaamc.dll
2009-04-14 00:23 . 2009-04-13 01:51 2535424 ----a-w c:\windows\system32\agsaamj.dll
2009-04-14 00:23 . 2009-04-13 01:51 1986560 ----a-w c:\windows\system32\akll.dll
2009-04-14 00:23 . 2009-04-13 01:51 196608 ----a-w c:\windows\system32\maag.dll
2009-04-14 00:23 . 2009-04-13 01:51 1245184 ----a-w c:\windows\system32\bkll.dll
2009-04-14 00:23 . 2009-04-13 01:51 1212416 ----a-w c:\windows\system32\ckll.dll
2009-04-13 23:49 . 2009-04-13 23:49 -------- d-----w c:\program files\Xilisoft
2009-04-13 01:29 . 2009-04-13 01:29 -------- d-----w c:\program files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
2009-03-25 22:55 . 2008-10-10 06:36 33280 ----a-w c:\windows\system32\identprv.dll
2009-03-18 06:30 . 2009-03-18 06:30 -------- d-----w c:\program files\Webteh
2009-03-03 04:40 . 2009-04-17 10:24 827392 ----a-w c:\windows\system32\wininet.dll
2009-03-03 04:37 . 2009-04-17 10:24 78336 ----a-w c:\windows\system32\ieencode.dll
2009-03-03 02:28 . 2009-04-17 10:24 26624 ----a-w c:\windows\system32\ieUnatt.exe
2009-02-20 01:27 . 2008-01-29 14:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-20 01:27 . 2009-02-20 00:47 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-02-20 01:27 . 2009-02-20 00:47 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-19 20:10 . 2009-02-19 20:10 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-02-19 20:10 . 2009-02-19 20:10 348160 ----a-w c:\windows\system32\msvcr71.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
2008-09-15 05:47 1784856 ----a-w c:\program files\P2P_Energy\tbP2P_.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{2BAE58C2-79F9-45D1-A286-81F911301C3A}"= "c:\program files\P2P_Energy\tbP2P_.dll" [2008-09-15 1784856]
[HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Uniblue RegistryBooster 2009"="c:\program files\uniblue\registrybooster\StartRegistryBooster.exe" [2008-08-26 99624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-20 206088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~2\mzvkbd.dll c:\progra~1\KASPER~1\KASPER~2\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~2\adialhk.dll c:\progra~1\KASPER~1\KASPER~2\kloehk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{0FFFB0C6-D564-4AD9-A626-C86F782E94B0}c:\\program files\\windows live\\messenger\\msnmsgr.exe"= UDP:c:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"UDP Query User{E5DBE5D7-EEF9-4BD9-B46D-8CA01F09154C}c:\\program files\\windows live\\messenger\\msnmsgr.exe"= TCP:c:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"{8E9D19EB-15FA-4562-85E0-C53B589275B0}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{1C9CDBD4-7F14-4BFC-BB80-2C01B8CE6578}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [29/01/08 17:29 33808]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [09/07/08 17:28 20496]
R2 ConfigFree Service;ConfigFree Service;c:\program files\Toshiba\ConfigFree\CFSvcs.exe [25/12/07 16:07 40960]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\Toshiba\SMARTLogService\TosIPCSrv.exe [03/12/07 19:03 126976]
R3 CnxtHdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service;c:\windows\System32\drivers\CHDART.sys [15/02/08 16:27 187904]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\System32\drivers\klfltdev.sys [13/03/08 18:02 26640]
R3 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [15/01/08 12:34 48472]
R3 QIOMem;Generic IO & Memory Access;c:\windows\System32\drivers\QIOMem.sys [09/04/07 18:13 8192]
RUnknown rpcnetp;rpcnetp; [x]
.
Contents of the 'Scheduled Tasks' folder
2009-05-16 c:\windows\Tasks\User_Feed_Synchronization-{940D89E4-45F8-49A9-9D11-A5E24B5D3F77}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Supplementary Scan -------
.
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA}
IE: {{F1624B5A-6FAF-4FA9-BE79-CDFAC2271976} - c:\program files\Pop up Blocker Pro\pdie.exe
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-17 00:21
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe
c:\windows\System32\rpcnetp.exe
c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\System32\TODDSrv.exe
c:\program files\Toshiba\Power Saver\TosCoSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\conime.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2009-05-16 0:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-16 21:24
ComboFix2.txt 2009-05-16 20:17
ComboFix3.txt 2008-11-16 10:24
ComboFix4.txt 2008-11-15 14:42
ComboFix5.txt 2009-05-16 21:15
Pre-Run: 54,461,800,448 bytes free
Post-Run: 54,260,154,368 bytes free
189 --- E O F --- 2009-05-14 22:37
وهذا التقرير