ComboFix 09-06-12.01 - Al-Qassabi 06/12/2009 22:05.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.968.1033.18.1023.638 [GMT 4:00]
Running from: e:\تقارير الهاجيك\combo fix\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\RECYCLER.exe
c:\windows\regedit.com
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\taskmgr.com
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Files Created from 2009-05-12 to 2009-06-12 )))))))))))))))))))))))))))))))
.
2009-06-12 10:40 . 2009-06-12 10:40 203776 ----a-w- c:\windows\system32\clrviddc.dll
2009-06-12 10:27 . 2009-06-12 10:27 -------- d-----w- c:\program files\Common Files\xing shared
2009-06-12 10:02 . 2009-06-12 10:02 390664 ----a-w- c:\documents and settings\Al-Qassabi\Application Data\Real\RealPlayer\setup\AU_setup.exe
2009-06-11 16:34 . 2009-06-11 16:34 -------- d-sh--w- c:\documents and settings\Al-Qassabi\IECompatCache
2009-06-11 15:03 . 2009-06-11 15:03 -------- d-----w- c:\windows\ie8updates
2009-06-11 13:40 . 2009-06-11 13:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-06-11 13:39 . 2009-06-11 13:39 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-11 07:30 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-11 07:30 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-11 07:30 . 2009-04-30 21:22 1985024 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-06-11 07:29 . 2009-04-30 21:22 11064832 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-06-09 07:14 . 2009-06-09 07:14 -------- d-sh--w- c:\documents and settings\Al-Qassabi\PrivacIE
2009-06-09 00:31 . 2009-06-09 00:31 -------- d-----w- c:\windows\system32\XPSViewer
2009-06-09 00:31 . 2009-06-09 00:31 -------- d-----w- c:\program files\Reference Assemblies
2009-06-09 00:30 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-06-09 00:30 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-06-09 00:29 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-06-09 00:29 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-06-09 00:29 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-06-09 00:29 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-06-09 00:29 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-06-09 00:19 . 2009-06-09 00:19 -------- d-sh--w- c:\documents and settings\Al-Qassabi\IETldCache
2009-06-08 20:32 . 2009-06-08 20:35 -------- dc-h--w- c:\windows\ie8
2009-06-04 08:02 . 2009-06-04 08:02 -------- d-----w- c:\program files\Common Files\SWF Studio
2009-06-04 07:22 . 2009-06-12 13:44 345996 ----a-w- C:\final.exe
2009-06-03 10:46 . 2009-06-03 10:46 390664 ----a-w- c:\documents and settings\Al-Qassabi\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-21 15:02 . 2009-05-21 18:57 38416 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\x64\klbg.sys
2009-05-21 15:02 . 2009-05-21 18:56 247312 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\Vista64\klif.sys
2009-05-21 15:02 . 2009-05-21 18:56 239120 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\Vista\klif.sys
2009-05-21 15:02 . 2009-05-21 18:56 218640 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP64\klif.sys
2009-05-21 15:02 . 2009-05-21 18:56 230032 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\w2000\klif.sys
2009-05-21 15:00 . 2009-05-21 18:54 44808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\fssync.dll
2009-05-21 14:59 . 2009-05-21 18:54 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\avp.exe
2009-05-21 14:59 . 2009-05-21 18:54 38416 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\x64\klbg.sys
2009-05-21 14:59 . 2009-05-21 18:54 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\klbg.sys
2009-05-21 14:59 . 2009-05-21 18:54 227856 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\Vista64\klif.sys
2009-05-21 14:59 . 2009-05-21 18:54 224272 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\Vista\klif.sys
2009-05-21 14:59 . 2009-05-21 18:54 202768 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\XP64\klif.sys
2009-05-21 14:59 . 2009-05-21 18:54 213520 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\XP\klif.sys
2009-05-21 14:59 . 2009-05-21 18:54 215824 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\w2000\klif.sys
2009-05-21 14:59 . 2009-05-21 18:53 38416 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\x64\klbg.sys
2009-05-21 14:59 . 2009-05-21 18:53 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\klbg.sys
2009-05-21 14:59 . 2009-05-21 18:53 227856 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\Vista64\klif.sys
2009-05-21 14:58 . 2009-05-21 18:53 224272 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\Vista\klif.sys
2009-05-21 14:58 . 2009-05-21 18:53 202768 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\XP64\klif.sys
2009-05-21 14:58 . 2009-05-21 18:53 213520 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\XP\klif.sys
2009-05-21 14:58 . 2009-05-21 18:53 215824 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\w2000\klif.sys
2009-05-21 14:54 . 2009-05-21 18:52 22792 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\x64\vkbd64.dll
2009-05-21 14:54 . 2009-05-21 18:52 60168 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\x64\ievkbd.dll
2009-05-21 14:53 . 2009-05-21 18:52 21256 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\vkbd.dll
2009-05-21 14:52 . 2009-05-21 18:51 861448 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\updater.dll
2009-05-21 14:51 . 2009-05-21 17:52 83208 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\mzvkbd.dll
2009-05-21 14:51 . 2009-05-21 17:52 62728 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\ievkbd.dll
2009-05-21 14:51 . 2009-05-21 17:52 43784 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\fssync.dll
2009-05-21 14:51 . 2009-05-21 17:52 365832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\ckahum.dll
2009-05-21 14:50 . 2009-05-21 17:50 201992 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\avp.exe
2009-05-13 19:55 . 2009-05-13 19:55 -------- d-----w- c:\documents and settings\Al-Qassabi\Incomplete
2009-05-13 19:55 . 2009-05-13 20:58 -------- d-----w- c:\documents and settings\Al-Qassabi\Application Data\LimeWire
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-12 18:22 . 2009-01-05 21:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-12 18:20 . 2009-01-05 21:15 7540 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-12 18:20 . 2009-01-05 21:15 663584 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-12 18:20 . 2009-01-05 21:15 32316 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-12 18:20 . 2009-01-05 21:15 3193376 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-12 13:15 . 2009-04-29 17:43 0 ----a-w- C:\osy3.sys
2009-06-12 12:26 . 2009-05-07 06:19 -------- d-----w- c:\documents and settings\Al-Qassabi\Application Data\Thinstall
2009-06-12 10:27 . 2008-10-22 19:47 -------- d-----w- c:\program files\Common Files\Real
2009-06-11 15:04 . 2008-10-23 11:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-11 14:14 . 2009-01-07 13:39 -------- d-----w- c:\documents and settings\Al-Qassabi\Application Data\cleaner
2009-06-09 09:15 . 2008-10-23 11:29 133680 ----a-w- c:\documents and settings\Al-Qassabi\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-08 19:47 . 2008-10-27 15:22 -------- d-----w- c:\program files\Microsoft Works
2009-05-31 18:23 . 2009-01-07 14:21 -------- d-----w- c:\program files\Common Files\delet
2009-05-29 05:26 . 2008-10-22 20:07 -------- d-----w- c:\program files\Common Files\InstallShield
2009-05-29 05:26 . 2008-10-22 20:08 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-21 18:57 . 2009-04-10 16:16 176656 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\x64\scrchpg.dll
2009-05-21 18:57 . 2009-02-05 19:20 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-05-21 18:56 . 2009-02-05 19:20 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
2009-05-21 18:56 . 2009-02-05 19:20 226832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
2009-05-21 18:55 . 2009-04-10 16:16 176656 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\x64\scrchpg.dll
2009-05-21 18:52 . 2009-04-10 16:15 176656 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\x64\scrchpg.dll
2009-05-20 15:47 . 2009-01-05 21:16 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-20 15:47 . 2009-01-05 21:16 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-13 05:15 . 2008-04-14 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-10 14:27 . 2008-11-08 17:44 -------- d-----w- c:\documents and settings\Al-Qassabi\Application Data\DMCache
2009-05-09 19:52 . 2008-10-22 19:47 -------- d-----w- c:\program files\Real
2009-05-09 19:48 . 2009-05-08 06:32 -------- d-----w- c:\documents and settings\Al-Qassabi\Application Data\COWON
2009-05-07 15:32 . 2008-04-14 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 06:20 . 2009-05-07 06:20 7168 ----a-w- c:\documents and settings\Al-Qassabi\Application Data\Thinstall\Dziobas Rar Player 0.008.12\400000a1c00003i\DZIOBAS.exe
2009-05-03 17:52 . 2009-05-03 17:33 -------- d-----w- c:\program files\Common Files\Adobe
2009-04-29 17:46 . 2009-04-06 11:23 -------- d-----w- c:\documents and settings\Al-Qassabi\Application Data\zzMicroWorld_Anti_Virus
2009-04-20 15:23 . 2009-04-20 15:21 63 ----a-w- c:\windows\AlfaStart.CMD
2009-04-20 15:21 . 2009-04-20 15:21 -------- d-----w- c:\program files\Alfa Autorun Killer 2
2009-04-19 15:54 . 2009-04-19 15:54 2015 ---h--r- c:\windows\system32\drivers\hosts
2009-04-17 18:46 . 2009-04-17 16:44 173648 ----a-w- c:\windows\hpoins28.dat
2009-04-17 16:51 . 2009-04-17 16:51 -------- d-----w- c:\program files\Hewlett-Packard
2009-04-17 16:50 . 2009-04-17 16:50 -------- d-----w- c:\program files\Common Files\HP
2009-04-17 16:47 . 2009-04-17 16:47 -------- d-----w- c:\program files\HP
2009-04-17 15:40 . 2008-10-24 09:45 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-04-17 12:26 . 2008-04-14 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-17 09:42 . 2009-03-13 10:19 -------- d-----w- c:\documents and settings\Al-Qassabi\Application Data\HPAppData
2009-04-15 14:51 . 2008-04-14 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-09 08:23 . 2008-10-22 19:47 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-04-09 08:23 . 2008-10-22 19:47 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-03-16 09:58 . 2009-03-16 09:58 4 ----a-w- c:\windows\RegDefrag.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-05 206088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-12 198160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"= ntbackup.exe
"2"= Regedit.exe
"3"= rstrui.exe
[HKLM\~\startupfolder\C:^Documents and Settings^Al-Qassabi^Start Menu^Programs^Startup^delxp.exe]
path=c:\documents and settings\Al-Qassabi\Start Menu\Programs\Startup\delxp.exe
backup=c:\windows\pss\delxp.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Al-Qassabi^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Al-Qassabi\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 05:29 م 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 06:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 05:06 م 24592]
S3 s816bus;Sony Ericsson Device 816 driver (WDM);c:\windows\system32\drivers\s816bus.sys [08/11/2008 06:34 م 81832]
S3 s816mdfl;Sony Ericsson Device 816 USB WMC Modem Filter;c:\windows\system32\drivers\s816mdfl.sys [08/11/2008 06:34 م 13864]
S3 s816mdm;Sony Ericsson Device 816 USB WMC Modem Driver;c:\windows\system32\drivers\s816mdm.sys [08/11/2008 06:34 م 107304]
S3 s816mgmt;Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s816mgmt.sys [08/11/2008 06:34 م 99112]
S3 s816nd5;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS);c:\windows\system32\drivers\s816nd5.sys [08/11/2008 06:35 م 21928]
S3 s816obex;Sony Ericsson Device 816 USB WMC OBEX Interface;c:\windows\system32\drivers\s816obex.sys [08/11/2008 06:34 م 97320]
S3 s816unic;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM);c:\windows\system32\drivers\s816unic.sys [08/11/2008 06:34 م 97704]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-12 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 13:04]
2009-06-12 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 13:04]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-csrss.exe - c:\windows\ctfmon.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = local
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-12 22:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):54,b0,68,ab,1e,69,54,9b,02,39,bd,96,bc,ca,62,30,7a,7c,67,e8,63,
dc,b5,66,c7,43,97,7c,f9,18,3e,a3,02,b0,05,bb,08,aa,4b,42,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{bd2d7cfb-62b3-4b0f-a395-b1aaceb13591}]
@Denied: (Full) (Everyone)
"Model"=dword:00000047
"Therad"=dword:0000001e
"MData"=hex(0):cb,9b,ad,ef,27,7d,29,69,f5,02,f0,76,aa,4a,f1,7c,d3,d9,67,7f,6a,
4b,7b,ad,04,7a,b1,b5,76,9b,27,47,e5,c0,4d,82,b8,7e,45,57,92,2d,3a,f2,f8,fd,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3732)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\CF23431.exe
.
**************************************************************************
.
Completion time: 2009-06-12 22:28 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-12 18:28
Pre-Run: 19,253,215,232 bytes free
Post-Run: 19,479,773,184 bytes free
255