:er:
كود:
ComboFix 08-04-11.5 - XPPRESP3 04/12/2008 3:24:42.1 - NTFSx86
Running from: C:\Documents and Settings\XPPRESP3\My Documents\My Completed Downloads\ComboFix.exe
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\pskill.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-12 to 2008-04-12 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-12 01:31 5,881,376 ----a-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-12 01:31 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-12 01:28 86,060 ----a-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-12 01:28 291,872 ----a-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-04-12 01:28 29,348 ----a-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-04-12 00:35 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\U3
2008-04-11 22:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-11 19:28 --------- d-----w C:\Program Files\Google
2008-04-11 19:17 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\uTorrent
2008-04-11 18:36 --------- d-----w C:\Program Files\Zards software
2008-04-11 16:39 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\ma-config.com
2008-04-11 15:34 --------- d-----w C:\Program Files\Intel
2008-04-11 14:50 21,361 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-04-11 14:50 21,361 ----a-w C:\WINDOWS\AegisP.sys
2008-04-11 14:50 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Intel
2008-04-11 14:50 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\Intel
2008-04-11 14:50 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Intel
2008-04-11 14:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intel
2008-04-11 13:53 --------- d-----w C:\Program Files\ma-config.com
2008-04-11 10:23 --------- d-----w C:\Program Files\SpeedBit Video Accelerator
2008-04-11 09:46 --------- d-----w C:\Program Files\uTorrent
2008-04-11 09:30 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\DMCache
2008-04-11 09:28 --------- d-----w C:\Program Files\Turbo Torrent
2008-04-11 09:24 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Orbit
2008-04-11 08:37 --------- d-----w C:\Program Files\VVSN
2008-04-11 02:03 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\CyberScrub
2008-04-11 02:02 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\cleaner
2008-04-10 23:42 --------- d-----w C:\Program Files\DAP
2008-04-10 23:21 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-04-10 21:58 --------- d-----w C:\Program Files\MSN Messenger
2008-04-10 21:58 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-09 19:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-04-09 19:16 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll
2008-04-09 12:33 --------- d-----w C:\Program Files\Microsoft.NET
2008-04-09 12:10 91,700 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-04-09 12:10 85,860 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-04-09 06:45 --------- d-----w C:\Program Files\IObit
2008-04-08 14:43 --------- d-----w C:\Program Files\ieSpell
2008-04-08 10:14 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-04-08 08:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-08 07:44 --------- d-----w C:\Program Files\Windows Defender
2008-04-08 07:29 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-08 07:26 --------- d-----w C:\Program Files\Bee Icons
2008-04-08 07:13 863,744 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-08 07:09 840,192 ----a-w C:\WINDOWS\system32\rasdlg.dll
2008-04-08 07:05 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-04-08 07:05 1,949,184 ----a-w C:\WINDOWS\system32\logonui.exe
2008-04-08 06:45 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-08 05:14 --------- d-----w C:\Program Files\Total Video Converter
2008-04-07 11:19 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Ahead
2008-04-07 07:51 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-07 07:50 --------- d-----w C:\Program Files\Windows Live
2008-04-07 07:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-05 16:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-04-05 13:12 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Nokia Multimedia Player
2008-04-04 09:52 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\bsplayer
2008-04-04 08:17 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\FlashFXP
2008-04-03 11:18 --------- d-----w C:\Program Files\MSXML 6.0
2008-04-03 11:14 --------- d-----w C:\Program Files\MSXML 4.0
2008-04-03 09:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-04-01 23:49 --------- d-----w C:\Program Files\Atheros
2008-04-01 23:46 --------- d-----w C:\Program Files\SigmaTel
2008-04-01 23:46 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-01 23:45 --------- d-----w C:\Program Files\Toshiba
2008-04-01 23:44 --------- d-----w C:\Program Files\ltmoh
2008-04-01 22:22 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Media Player Classic
2008-04-01 22:14 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\PC Suite
2008-04-01 22:14 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Nokia
2008-04-01 22:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-04-01 22:12 --------- d-----w C:\Program Files\Nokia
2008-04-01 22:12 --------- d-----w C:\Program Files\DIFX
2008-04-01 22:12 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-04-01 22:12 --------- d-----w C:\Program Files\Common Files\Nokia
2008-04-01 22:11 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-04-01 22:08 --------- d-----w C:\Program Files\Kaspersky Lab
2008-04-01 21:30 --------- d-----w C:\Program Files\Zuma Deluxe
2008-04-01 21:30 --------- d-----w C:\Program Files\Winamp
2008-04-01 21:30 --------- d-----w C:\Program Files\win32pad_1_5_10
2008-04-01 21:30 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Gena01
2008-04-01 21:29 --------- d-----w C:\Program Files\Java
2008-04-01 21:29 --------- d-----w C:\Program Files\Common Files\Java
2008-04-01 21:26 --------- d-----w C:\Program Files\Nero
2008-04-01 21:26 --------- d-----w C:\Program Files\Common Files\Ahead
2008-04-01 21:09 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-04-01 21:09 --------- d-----w C:\Program Files\FolderSize
2008-04-01 21:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-01 21:08 --------- d-----w C:\Program Files\Desktop
2008-04-01 21:04 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\ACD Systems
2008-04-01 20:56 --------- d-----w C:\Program Files\DAMN NFO Viewer
2008-04-01 20:52 --------- d-----w C:\Program Files\Unlocker
2008-04-01 20:52 --------- d-----w C:\Program Files\Graphics
2008-03-19 09:40 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-20 18:49 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 06:52 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
.
[code]<pre>
----a-r 4,008,488 2004-07-21 20:45:30 C:\Documents and Settings\XPPRESP3\My Documents\vbulletin\برنامج ارسال ايميلات\AMS42\AMS42 .EXE
</pre>
------- Sigcheck -------
04/08/2008 09:09 AM 1656832 bf46f81e57be7ea8b5800fab06a06332 C:\WINDOWS\explorer.exe
10/15/2005 01:07 PM 1032192 45757077a47c68a603a79b03a1a836ab C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
06/13/2007 12:23 PM 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\SP2GDR\explorer.exe
06/13/2007 01:26 PM 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\SP2QFE\explorer.exe
04/08/2008 09:09 AM 1656832 bf46f81e57be7ea8b5800fab06a06332 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 06:00 PM 15360]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [12/10/2007 10:12 AM 695808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"TFncKy"="TFncKy.exe" []
"00THotkey"="C:\WINDOWS\system32\
00THotkey.exe" [02/25/2004 02:12 PM 258048]
"000StTHK"="000StTHK.exe" [06/23/2001 08:28 PM 24576 C:\WINDOWS\system32\
000StTHK.exe]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [01/02/2003 04:16 PM 172032]
"AGRSMMSG"="AGRSMMSG.exe" [04/18/2003 11:20 AM 88363 C:\WINDOWS\agrsmmsg.exe]
"TPSMain"="TPSMain.exe" [03/03/2004 12:57 PM 278528 C:\WINDOWS\system32\TPSMain.exe]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [08/03/2003 04:01 PM 86073]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [01/26/2004 07:03 PM 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [01/26/2004 07:03 PM 118784]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe" [05/03/2006 02:56 AM 36975]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [11/03/2006 07:20 PM 866584]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 06:00 PM 110592 C:\WINDOWS\system32\bthprops.cpl]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [06/28/2007 12:51 PM 218376]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.exe" [04/09/2008 09:16 PM 3057152]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [10/08/2007 02:18 PM 995328]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [10/08/2007 02:13 PM 1101824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 06:00 PM 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [11/07/2007 05:35 PM 1294336]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [03/13/2007 04:38 PM 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
antiwpa.dll 07/22/2006 11:49 PM 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsp_lmwl]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Nero\\Nero Core\\nero.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\SpeedBit Video Accelerator\\VideoAccelerator.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\SpeedBit Video Accelerator\\VideoAcceleratorEngine.exe"=
R2 sbbotdi;sbbotdi;C:\PROGRA~1\SPEEDB~1\sbbotdi.sys [04/09/2008 09:20 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WudfServiceGroup REG_SZ hex(7):57,00,55,00,44,00,46,00,53,00,76,00,63,00,00,00,00,00
.
*******s of the 'Scheduled Tasks' folder
"2008-04-12 01:32:42 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-04-12 03:30:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\snmp.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 04/12/2008 3:36:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-12 01:36:40
Pre-Run: 33,551,634,432 bytes free
Post-Run: 33,556,525,056 bytes free
.
2008-04-09 05:47:10 --- E O F ---
[/CODE]