ComboFix 09-06-23.01 - jabooor 06/25/2009 8:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.973.1033.18.191.85 [GMT 3:00]
Running from: c:\documents and settings\jabooor\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\kl1.sys
D:\desktop.ini
.
((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-06-25 )))))))))))))))))))))))))))))))
.
2009-06-25 08:37 . 2008-10-16 11:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-06-25 08:37 . 2008-10-16 11:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-06-25 08:37 . 2009-06-25 08:44 -------- d-----w- c:\windows\LastGood
2009-06-25 01:24 . 2009-06-25 01:24 -------- d-----w- c:\program files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-25 10:47 . 2009-06-24 19:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-25 10:46 . 2009-06-24 19:20 335904 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-25 10:46 . 2009-06-24 19:20 3276 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-25 06:10 . 2009-06-24 19:20 10920 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-25 05:54 . 2009-06-24 19:20 1125408 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-25 05:35 . 2009-06-24 14:47 27264 ----a-w- c:\documents and settings\jabooor\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-25 00:42 . 2009-06-25 00:42 -------- d-----w- c:\program files\microsoft frontpage
2009-06-25 00:40 . 2009-06-25 00:40 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-25 00:37 . 2009-06-25 00:37 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-06-24 23:45 . 2009-06-24 23:44 -------- d-----w- c:\program files\BitComet
2009-06-24 23:14 . 2009-06-24 23:14 -------- d-----w- c:\program files\Bonjour
2009-06-24 23:14 . 2009-06-24 20:11 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-24 23:03 . 2009-06-24 23:03 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-06-24 22:51 . 2009-06-24 20:52 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-24 22:22 . 2009-06-24 20:49 -------- d-----w- c:\documents and settings\jabooor\Application Data\Skype
2009-06-24 21:45 . 2009-06-24 21:45 130 ----a-w- c:\documents and settings\jabooor\Local Settings\Application Data\fusioncache.dat
2009-06-24 21:45 . 2009-06-24 21:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-06-24 21:03 . 2009-06-24 21:03 -------- d-----w- c:\program files\Circle Developement
2009-06-24 21:03 . 2009-06-24 21:03 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-24 21:02 . 2009-06-24 20:06 -------- d-----w- c:\program files\Google
2009-06-24 21:00 . 2009-06-24 20:50 -------- d-----w- c:\program files\Windows Live
2009-06-24 20:58 . 2009-06-24 20:57 -------- d-----w- c:\program files\Hotspot Shield
2009-06-24 20:56 . 2004-09-28 03:38 114688 ----a-w- c:\windows\system32\wmatimer.dll
2009-06-24 20:56 . 2009-06-24 20:56 -------- d-----w- c:\program files\Easy RM to MP3 Converter
2009-06-24 20:56 . 2009-06-24 20:55 -------- d-----w- c:\program files\Video Convert Master
2009-06-24 20:55 . 2009-06-24 20:55 47360 ----a-w- c:\windows\system32\drivers\Pcouffin.sys
2009-06-24 20:52 . 2009-06-24 20:50 -------- dcsh--w- c:\program files\Common Files\WindowsLiveInstaller
2009-06-24 20:50 . 2009-06-24 20:50 -------- d-----w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-06-24 20:48 . 2009-06-24 20:48 -------- d-----r- c:\program files\Skype
2009-06-24 20:48 . 2009-06-24 20:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-06-24 20:48 . 2009-06-24 20:48 -------- d-----w- c:\program files\Common Files\Skype
2009-06-24 20:46 . 2009-06-24 20:46 -------- d-----w- c:\program files\Golden Al-Wafi Translator
2009-06-24 20:45 . 2009-06-24 20:45 172032 ------w- c:\windows\Setup1.exe
2009-06-24 20:45 . 2009-06-24 20:45 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-06-24 20:42 . 2009-06-24 20:25 104156 ----a-w- c:\windows\hpoins04.dat
2009-06-24 20:40 . 2009-06-24 20:27 -------- d-----w- c:\program files\HP
2009-06-24 20:38 . 2009-06-24 20:38 -------- d-----w- c:\program files\Common Files\HP
2009-06-24 20:36 . 2009-06-24 20:36 -------- d-----w- c:\program files\Hewlett-Packard
2009-06-24 20:36 . 2009-06-24 20:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-06-24 20:36 . 2009-06-24 20:36 45056 ----a-r- c:\documents and settings\jabooor\Application Data\Microsoft\Installer\{457791C5-D702-4143-A7B2-2744BE9573F2}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe
2009-06-24 20:35 . 2009-06-24 20:35 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-06-24 20:07 . 2009-06-24 20:07 -------- d-----w- c:\program files\Common Files\xing shared
2009-06-24 20:07 . 2009-06-24 20:06 -------- d-----w- c:\program files\Common Files\Real
2009-06-24 20:06 . 2009-06-24 20:06 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-06-24 20:06 . 2009-06-24 20:06 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-06-24 20:06 . 2009-06-24 20:06 -------- d-----w- c:\program files\Real
2009-06-24 20:04 . 2009-06-24 20:04 2232 ----a-w- c:\windows\java\Packages\Data\R3XV5ZLR.DAT
2009-06-24 20:04 . 2009-06-24 20:04 155995 ----a-w- c:\windows\java\Packages\MXZN9RZP.ZIP
2009-06-24 20:04 . 2009-06-24 20:04 2678 ----a-w- c:\windows\java\Packages\Data\RFHF7NPN.DAT
2009-06-24 20:04 . 2009-06-24 20:04 2678 ----a-w- c:\windows\java\Packages\Data\V5V7RLBL.DAT
2009-06-24 20:04 . 2009-06-24 20:04 2678 ----a-w- c:\windows\java\Packages\Data\FJXBZTBB.DAT
2009-06-24 20:04 . 2009-06-24 20:04 2678 ----a-w- c:\windows\java\Packages\Data\7V975RNP.DAT
2009-06-24 20:04 . 2009-06-24 20:04 2678 ----a-w- c:\windows\java\Packages\Data\4G813TZB.DAT
2009-06-24 19:54 . 2009-06-24 19:54 32784 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\update\rollback\AutoPatches\kav8exec\8.0.0.506\klbg.sys
2009-06-24 19:54 . 2009-06-24 19:54 227344 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\update\rollback\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
2009-06-24 19:54 . 2009-06-24 19:54 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\update\rollback\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-06-24 19:54 . 2008-01-29 14:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-06-24 19:54 . 2009-06-24 19:21 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-06-24 19:54 . 2009-06-24 19:21 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-06-24 19:54 . 2009-06-24 19:54 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
2009-06-24 19:54 . 2009-06-24 19:54 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-06-24 19:54 . 2009-06-24 19:54 226832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
2009-06-24 19:20 . 2009-06-24 19:20 -------- d-----w- c:\program files\Kaspersky Lab
2009-06-24 19:18 . 2009-06-24 19:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-04-29 04:56 . 2004-08-04 01:07 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 01:07 78336 ------w- c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-06-24 20:57 204248 ----a-w- c:\program files\Hotspot Shield\HssIE\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-24 39408]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-06-24 206088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-24 185896]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]
«©م، ¢¬نïé Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10981:TCP"= 10981:TCP:BitComet 10981 TCP
"10981:UDP"= 10981:UDP:BitComet 10981 UDP
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [1/29/2008 5:29 م 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [3/13/2008 6:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [4/30/2008 5:06 م 24592]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-RegistryMechanic - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.bh/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-25 13:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\HPZipm12.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\program files\HP\hpcoretech\comp\hpdarc.exe
.
**************************************************************************
.
Completion time: 2009-06-25 13:51 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-25 10:51
Pre-Run: 27,574,710,272 bytes free
Post-Run: 26,904,952,832 bytes free
163 --- E O F --- 2009-06-24 15:34