ComboFix 09-07-07.01 - ME 07/07/2009 21:21.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.1918.1572 [GMT -7:00]
Running from: c:\documents and settings\ME\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\driver
.
((((((((((((((((((((((((( Files Created from 2009-06-08 to 2009-07-08 )))))))))))))))))))))))))))))))
.
2009-07-08 02:39 . 2009-07-08 02:39 -------- d-----w- c:\program files\Trend Micro
2009-07-07 21:19 . 2009-07-07 21:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Motive
2009-07-07 06:15 . 2003-05-22 23:31 55808 ----a-w- c:\windows\system32\lfpsd13n.dll
2009-07-07 06:15 . 2003-11-04 22:10 65536 ----a-w- c:\windows\system32\lfeps13n.dll
2009-07-07 06:15 . 2003-11-04 22:10 69632 ----a-w- c:\windows\system32\lfgif13n.dll
2009-07-07 06:15 . 2004-05-14 23:53 450560 ----a-w- c:\windows\system32\ltimg13n.dll
2009-07-07 06:15 . 2004-05-14 23:53 57344 ----a-w- c:\windows\system32\lfbmp13n.dll
2009-07-07 06:15 . 2004-05-14 23:53 401408 ----a-w- c:\windows\system32\lfcmp13n.dll
2009-07-07 06:15 . 2004-01-12 09:09 206336 ----a-w- c:\windows\system32\ltefx13n.dll
2009-07-07 06:15 . 2004-05-14 23:53 462848 ----a-w- c:\windows\system32\ltkrn13n.dll
2009-07-07 06:15 . 2004-05-14 23:53 299008 ----a-w- c:\windows\system32\ltdis13n.dll
2009-07-07 06:15 . 2004-05-14 23:53 163840 ----a-w- c:\windows\system32\ltfil13n.dll
2009-07-07 05:48 . 2007-10-30 23:32 20992 -c--a-w- c:\windows\system32\dllcache\rtl8139.sys
2009-07-07 05:48 . 2007-10-30 23:32 20992 ----a-w- c:\windows\system32\drivers\RTL8139.sys
2009-07-06 23:57 . 2009-07-07 00:06 2817144 ----a-w- c:\documents and settings\ME\Application Data\IDM\DwnlData\ME\kingooo_hijackthis_aio_82\kingooo_hijackthis_aio.exe
2009-07-06 05:15 . 2007-03-22 10:46 126976 ----a-w- c:\documents and settings\ME\Application Data\GRETECH\GomPlayer\GrLauncher.exe
2009-07-06 05:15 . 2009-07-06 05:15 -------- d-----w- c:\documents and settings\All Users\Application Data\GRETECH
2009-07-06 05:14 . 2009-07-06 05:14 -------- d-----w- c:\documents and settings\ME\Application Data\GRETECH
2009-07-06 05:14 . 2009-07-06 05:14 -------- d-----w- c:\program files\GRETECH
2009-07-05 06:21 . 2009-07-05 06:21 -------- d-----w- c:\documents and settings\ME\Application Data\Media Player Classic
2009-07-04 17:07 . 2009-07-05 04:24 -------- d-----w- c:\documents and settings\ME\Local Settings\Application Data\Adobe
2009-07-04 13:32 . 2009-07-08 04:25 -------- d-----w- c:\documents and settings\ME\Tracing
2009-07-04 08:36 . 2009-07-05 18:35 57872 ----a-w- c:\documents and settings\ME\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-04 08:35 . 2007-01-11 10:20 194304 ----a-r- c:\windows\system32\drivers\RTL8187.sys
2009-07-04 08:33 . 2006-05-04 23:26 2808832 ----a-w- c:\windows\alcwzrd.exe
2009-07-04 08:33 . 2005-05-04 01:43 69632 ----a-w- c:\windows\Alcmtr.exe
2009-07-04 08:33 . 2007-10-17 01:30 16855552 ----a-w- c:\windows\RTHDCPL.exe
2009-07-04 08:33 . 2007-10-11 18:04 1826816 ----a-w- c:\windows\SkyTel.exe
2009-07-04 08:33 . 2007-06-28 23:44 2165760 ----a-w- c:\windows\MicCal.exe
2009-07-04 08:33 . 2006-07-21 23:14 86016 ----a-w- c:\windows\SoundMan.exe
2009-07-04 08:33 . 2009-07-04 08:33 -------- d-----w- c:\windows\system32\RTCOM
2009-07-04 08:33 . 2007-10-17 01:38 4615168 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2009-07-04 08:33 . 2007-07-27 01:06 1191936 ----a-w- c:\windows\RtlUpd.exe
2009-07-04 08:33 . 2007-03-24 02:19 9715200 ----a-w- c:\windows\RTLCPL.exe
2009-07-04 08:33 . 2006-08-01 22:02 49152 ----a-w- c:\windows\system32\ChCfg.exe
2009-07-04 08:32 . 2009-07-04 08:32 -------- d-----w- c:\program files\Realtek
2009-07-04 08:32 . 2009-07-04 08:32 315392 ----a-w- c:\windows\HideWin.exe
2009-07-04 08:32 . 2007-07-27 00:09 520192 ----a-w- c:\windows\RtlExUpd.dll
2009-07-04 08:32 . 2003-04-30 04:07 306688 ----a-w- c:\windows\IsUninst.exe
2009-07-04 08:31 . 2009-07-04 08:31 -------- d-----w- c:\program files\S3
2009-07-04 08:31 . 2009-07-04 08:32 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-04 08:31 . 2007-10-18 10:28 52224 ----a-r- c:\windows\system32\drivers\ViPrt.sys
2009-07-04 08:31 . 2007-10-18 10:28 16896 ----a-r- c:\windows\system32\drivers\ViBus.sys
2009-07-04 08:31 . 2007-09-21 08:28 18432 ----a-r- c:\windows\system32\vIdeInst.dll
2009-07-04 08:31 . 2007-09-21 09:49 9216 ----a-r- c:\windows\system32\drivers\videX32.sys
2009-07-04 08:30 . 2009-07-04 08:30 -------- d-----w- c:\program files\VIA
2009-07-04 08:30 . 2007-09-20 02:43 331184 ------w- c:\windows\system32\difxapi.dll
2009-07-04 08:30 . 2009-07-04 08:31 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-04 08:30 . 2005-03-16 06:23 13696 ----a-r- c:\windows\system32\drivers\BIOS.sys
2009-07-04 08:29 . 2009-07-03 09:58 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-07-04 08:29 . 2009-07-03 09:58 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-07-04 08:28 . 2009-07-08 04:25 996384 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-04 08:28 . 2009-07-08 04:25 237600 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-07-04 08:28 . 2009-07-08 04:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-04 08:28 . 2009-07-04 08:28 -------- d-----w- c:\program files\Kaspersky Lab
2009-07-04 08:28 . 2009-07-04 08:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-07-04 08:26 . 2007-10-31 01:47 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2009-07-04 08:22 . 2009-07-04 08:22 -------- d-----w- c:\windows\system32\wbem\MUI
2009-07-04 08:21 . 2001-08-22 18:59 57344 ----a-w- c:\windows\system32\WMErrAra.dll
2009-07-04 08:13 . 2007-04-03 06:56 19456 -c--a-w- c:\windows\system32\dllcache\agt0401.dll
2009-07-04 08:13 . 2007-04-03 06:56 19456 -c--a-w- c:\windows\system32\dllcache\agt040d.dll
2009-07-04 08:12 . 2009-07-04 08:12 -------- d-----w- c:\windows\ServicePackFiles
2009-07-04 08:12 . 2007-10-31 07:32 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2009-07-04 08:09 . 2007-08-11 03:46 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2009-07-04 08:04 . 2009-07-04 08:04 -------- d-s---w- c:\windows\system32\Microsoft
2009-07-04 08:04 . 2009-07-04 08:19 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Microsoft
2009-07-04 08:01 . 2001-08-23 16:00 6656 -c--a-w- c:\windows\system32\dllcache\iissync.exe
2009-07-04 08:00 . 2009-07-04 08:00 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-08 04:25 . 2009-07-04 08:28 10960 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-08 04:25 . 2009-07-03 11:17 -------- d-----w- c:\documents and settings\ME\Application Data\DMCache
2009-07-08 04:25 . 2009-07-04 08:28 3988 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-07-06 11:57 . 2009-07-03 11:17 -------- d-----w- c:\documents and settings\ME\Application Data\IDM
2009-07-06 05:55 . 2009-07-03 09:59 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-04 08:21 . 2009-07-04 08:00 166455 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-04 08:01 . 2009-07-04 08:01 -------- d-----w- c:\program files\microsoft frontpage
2009-07-04 07:57 . 2009-07-04 07:57 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-07-03 11:18 . 2009-07-03 11:18 198064 ----a-w- c:\documents and settings\ME\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-07-03 11:17 . 2009-07-03 11:17 -------- d-----w- c:\program files\MatriX
2009-07-03 11:17 . 2009-07-03 11:17 -------- d-----w- c:\program files\Internet Download Manager
2009-07-03 10:04 . 2009-07-03 10:04 -------- d-----w- c:\program files\XP Codec Pack
2009-07-03 10:03 . 2009-07-03 10:02 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-07-03 10:02 . 2009-07-03 10:01 -------- d-----w- c:\program files\Windows Live
2009-07-03 10:00 . 2009-07-03 10:00 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-07-03 09:58 . 2008-01-30 00:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-07-03 09:58 . 2009-07-03 09:58 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-07-03 09:58 . 2009-07-03 09:58 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
2009-07-03 09:58 . 2009-07-03 09:58 226832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
2009-07-03 09:53 . 2009-07-03 09:48 -------- d-----w- c:\program files\Paltalk Messenger
2009-07-03 09:49 . 2009-07-03 09:48 -------- d-----w- c:\documents and settings\ME\Application Data\Paltalk
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2007-10-31 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-05-28 2815408]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-07 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-07-03 206088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2006-09-21 53248]
"S3Trayp"="S3trayp.exe" - c:\windows\system32\S3Trayp.exe [2007-06-11 176128]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-10-17 16855552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-10-31 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-7-5 113664]
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2009-6-29 11536384]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-9-10 525664]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 05:29 م 33808]
R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [04/07/2009 01:31 ص 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [04/07/2009 01:31 ص 52224]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [04/07/2009 01:30 ص 13696]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 06:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 05:06 م 24592]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [11/07/2007 01:08 م 714240]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [04/07/2009 01:35 ص 194304]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Settings,ProxyOverride = local
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-07 21:25
Windows 5.1.2600 Service Pack 3, v.3244 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-08 21:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-08 04:27
Pre-Run: 25,111,961,600 bytes free
Post-Run: 26,059,489,280 bytes free
176