ComboFix 09-06-07.01 - Bader 06/07/2009 23:20.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1279.804 [GMT 3:00]
Running from: c:\users\Bader\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
.
2009-06-08 01:51 . 2009-06-07 14:55 -------- d-----w- c:\windows\Panther
2009-06-08 01:50 . 2009-06-08 01:50 -------- d-sh--w- C:\Boot
2009-06-08 01:50 . 2009-06-08 01:50 -------- d-sh--w- \Boot
2009-06-08 00:51 . 2009-06-07 19:44 1655255040 --sha-w- \pagefile.sys
2009-06-08 00:51 . 2009-06-07 17:49 -------- d-sh--w- \System Volume Information
2009-06-07 20:22 . 2009-06-07 20:22 -------- d-----w- c:\users\Bader\AppData\Local\temp
2009-06-07 20:22 . 2009-06-07 20:22 -------- d-----w- C:\temp
2009-06-07 20:22 . 2009-06-07 20:22 -------- d-----w- \temp
2009-06-07 17:50 . 2009-06-07 17:50 96976 ----a-w- c:\windows\system32\drivers\klin.dat
2009-06-07 17:50 . 2009-06-07 17:50 87855 ----a-w- c:\windows\system32\drivers\klick.dat
2009-06-07 17:50 . 2009-06-07 19:37 -------- d-----w- c:\programdata\Kaspersky Lab
2009-06-07 17:50 . 2009-06-07 17:50 32 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-07 17:50 . 2009-06-07 17:50 32 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-07 17:50 . 2009-06-07 17:50 -------- d-----w- c:\program files\Kaspersky Lab
2009-06-07 17:50 . 2009-06-07 17:50 -------- d-sh--w- \Config.Msi
2009-06-07 17:49 . 2009-06-07 17:50 -------- d-sh--w- c:\windows\Installer
2009-06-07 17:49 . 2009-06-07 17:49 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2009-06-07 15:04 . 2009-06-07 15:04 48600 ----a-w- c:\users\Bader\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-07 15:02 . 2008-10-16 21:13 1809944 ----a-w- c:\windows\system32\wuaueng.dll
2009-06-07 15:02 . 2008-10-16 21:09 51224 ----a-w- c:\windows\system32\wuauclt.exe
2009-06-07 15:02 . 2008-10-16 21:09 43544 ----a-w- c:\windows\system32\wups2.dll
2009-06-07 15:02 . 2008-10-16 20:56 1524736 ----a-w- c:\windows\system32\wucltux.dll
2009-06-07 15:02 . 2009-06-07 17:50 -------- d-----w- c:\users\Bader
2009-06-07 14:57 . 2009-06-07 05:01 -------- d-----w- c:\windows\Debug
2009-06-07 14:56 . 2009-06-07 19:44 1341448192 --sha-w- \hiberfil.sys
2009-06-07 04:58 . 2008-10-16 21:12 561688 ----a-w- c:\windows\system32\wuapi.dll
2009-06-07 04:58 . 2008-10-16 21:08 34328 ----a-w- c:\windows\system32\wups.dll
2009-06-07 04:58 . 2008-10-16 20:55 83456 ----a-w- c:\windows\system32\wudriver.dll
2009-06-07 04:58 . 2008-10-16 11:08 162064 ----a-w- c:\windows\system32\wuwebv.dll
2009-06-07 04:58 . 2008-10-16 10:56 31232 ----a-w- c:\windows\system32\wuapp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-07 19:44 . 2009-06-08 00:51 1655255040 --sha-w- \pagefile.sys
2009-06-07 19:44 . 2009-06-07 14:56 1341448192 --sha-w- \hiberfil.sys
2009-06-07 17:50 . 2009-06-07 17:50 32 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-07 17:50 . 2009-06-07 17:50 32 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-04-11 13:23 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-04-11 13:23 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-04-11 13:23 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-04-11 13:23 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-04-11 13:23 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-04-11 13:23 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-04-11 13:23 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-04-11 13:22 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-04-11 13:18 . 2009-04-11 13:18 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-07_19.41.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-11-02 13:05 . 2009-06-07 20:19 57998 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-06-07 15:04 . 2009-06-07 20:19 2132 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-120262201-1180521294-2031832978-1001_UserData.bin
- 2009-06-07 16:28 . 2009-06-07 19:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-06-07 16:28 . 2009-06-07 19:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-06-07 16:28 . 2009-06-07 19:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-06-07 16:28 . 2009-06-07 19:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2006-11-02 10:33 . 2009-06-07 17:42 595446 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-06-07 19:49 595446 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-06-07 19:49 101144 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-06-07 17:42 101144 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnhancedStorageShell]
@="{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}"
[HKEY_CLASSES_ROOT\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}]
2009-04-11 13:18 114176 ----a-w- c:\windows\System32\EhStorShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"BindDirectlyToPropertySetStorage"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):62,22,80,d4,a9,ba,c9,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [1/29/2008 5:29 PM 32784]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [7/9/2008 5:28 PM 20496]
R3 GKUPRO2D;GKUPRO2D;c:\windows\System32\drivers\GKUPRO2D.sys [2/18/2005 11:57 AM 71168]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\System32\drivers\klfltdev.sys [3/13/2008 6:02 PM 26640]
R3 NmPar;MosChip PCI Parallel Port;c:\windows\System32\drivers\NmPar.sys [12/19/2006 6:22 AM 81408]
R3 nmserial;MosChip PCI Serial Port;c:\windows\System32\drivers\NmSerial.sys [12/19/2006 6:20 AM 63488]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - KLBG
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = about:blank
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-07 23:22
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-06-07 23:23
ComboFix-quarantined-files.txt 2009-06-07 20:23
ComboFix2.txt 2009-06-07 19:42
Pre-Run: 147,726,245,888 bytes free
Post-Run: 147,705,843,712 bytes free
121 --- E O F --- 2009-06-07 17:41