اتفضل حضرتك
ComboFix 09-12-17.01 - UnLimited 12/18/2009 2:32.1.1 - FAT32x86
Running from: c:\documents and settings\UnLimited\My Documents\Downloads\Programs\KittyFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\UNLIMI~1\LOCALS~1\Temp\E_N4
c:\docume~1\UNLIMI~1\LOCALS~1\Temp\E_N4\cnvpe.fne
c:\docume~1\UNLIMI~1\LOCALS~1\Temp\E_N4\dp1.fne
c:\docume~1\UNLIMI~1\LOCALS~1\Temp\E_N4\eAPI.fne
c:\docume~1\UNLIMI~1\LOCALS~1\Temp\E_N4\HtmlView.fne
c:\docume~1\UNLIMI~1\LOCALS~1\Temp\E_N4\internet.fne
c:\docume~1\UNLIMI~1\LOCALS~1\Temp\E_N4\krnln.fnr
c:\docume~1\UNLIMI~1\LOCALS~1\Temp\E_N4\shell.fne
c:\docume~1\UNLIMI~1\LOCALS~1\Temp\E_N4\spec.fne
c:\documents and settings\UnLimited\Local Settings\Application Data\DoubleD
c:\documents and settings\UnLimited\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
c:\program files\outlook express\svchost.exe
c:\windows\hinhem.scr
c:\windows\scvhost.exe
c:\windows\system32\autorun.ini
c:\windows\system32\blastclnnn.exe
c:\windows\system32\scvhost.exe
c:\windows\system32\setting.ini
F:\MaJMoafatawa01.exe
c:\windows\system32\srsvc.dll . . . is infected!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IMAPISERVICE
-------\Service_ImapiService
((((((((((((((((((((((((( Files Created from 2009-11-18 to 2009-12-18 )))))))))))))))))))))))))))))))
.
2009-12-17 23:56 . 2009-12-17 23:56 -------- d-----w- c:\documents and settings\UnLimited\Local Settings\Application Data\Runscanner.net
2009-12-14 17:06 . 2009-12-14 17:06 -------- d-----w- c:\program files\Common Files\PCSuite
2009-12-14 17:06 . 2009-12-14 17:06 -------- d-----w- c:\program files\Common Files\Nokia
2009-12-14 17:04 . 2008-08-26 07:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-12-14 17:04 . 2009-12-14 17:04 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-14 17:01 . 2009-12-14 16:59 34429264 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_eng.exe
2009-12-14 17:00 . 2009-12-14 17:00 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\pcswpcsi.exe
2009-12-14 17:00 . 2009-12-14 17:00 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstCCD.exe
2009-12-14 17:00 . 2009-12-14 17:00 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-12-14 17:00 . 2009-12-14 17:00 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCS.exe
2009-11-19 11:42 . 2009-11-19 11:42 -------- d-----w- c:\documents and settings\UnLimited\Local Settings\Application Data\Opera
2009-11-19 11:41 . 2009-11-19 11:41 -------- d-----w- c:\program files\Opera 10.10 Beta
2009-11-18 21:41 . 2009-11-18 21:41 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-11-18 21:41 . 2009-11-18 21:41 -------- d-----w- c:\documents and settings\UnLimited\Application Data\skypePM
2009-11-18 21:36 . 2009-11-18 21:36 -------- d-----w- c:\documents and settings\UnLimited\Application Data\Skype
2009-11-18 21:23 . 2009-11-18 21:23 -------- d-----w- c:\program files\Common Files\Skype
2009-11-18 21:23 . 2009-11-18 21:23 -------- d-----r- c:\program files\Skype
2009-11-18 21:21 . 2009-11-18 21:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-28 19:02 . 2009-07-11 16:55 10 ----a-w- c:\windows\popcinfo.dat
2009-11-07 22:48 . 2009-11-07 22:48 -------- d-----w- c:\program files\mp3DirectCut
2009-10-28 10:15 . 2009-09-09 21:02 579048 ----a-w- c:\documents and settings\UnLimited\Application Data\IDM\DwnlData\UnLimited\fsbl_53\fsbl.exe
2009-10-06 09:52 . 2009-07-06 14:19 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-09-20 20:18 . 2009-07-04 21:23 90112 ----a-w- c:\windows\DUMP48a1.tmp
2009-09-10 00:54 . 2009-09-02 15:24 20992 --sh--w- c:\windows\system32\8945AB\d83a70.exe
.
------- Sigcheck -------
[-] 2008-11-17 . 2F945D4B5980B4C3E8E08D44B0BF7BF3 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
c:\windows\System32\wuauclt.exe ... is missing !!
c:\windows\System32\srsvc.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-09-19 4347120]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-09-09 3114416]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-24 180269]
"FED086"="c:\windows\system32\F54D20\FED086.EXE" [2009-10-18 1405835]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2008-04-13 99840]
c:\documents and settings\UnLimited\Start Menu\Programs\Startup\
FED086.lnk - c:\windows\system32\F54D20\FED086.EXE [2009-10-18 1405835]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\Program Files\\Nokia\\Nokia PC Suite 7\\PCSuite.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Internet Download Manager\\IEMonitor.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\ymsgr_tray.exe"=
"c:\\WINDOWS\\system32\\8945AB\\XX-9249D.EXE"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Yahoo!\\YUPDATER\\YUPDATER.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Opera 10.10 Beta\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [7/6/2009 5:08 PM 54752]
S1 avfwot;avfwot;c:\windows\system32\DRIVERS\avfwot.sys --> c:\windows\system32\DRIVERS\avfwot.sys [?]
S3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\mrkjj.sys --> c:\windows\system32\drivers\mrkjj.sys [?]
S3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys --> c:\windows\system32\DRIVERS\avfwim.sys [?]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.eg/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
TCP: {6CEADF0A-8BBB-4E53-895B-8C3095B541B5} = 163.121.128.134,163.121.128.135
FF - ProfilePath - c:\documents and settings\UnLimited\Application Data\Mozilla\Firefox\Profiles\cwury2qk.default\
FF - component: c:\documents and settings\UnLimited\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Opera 10.10 Beta\program\plugins\npdsplay.dll
FF - plugin: c:\program files\Opera 10.10 Beta\program\plugins\npwmsdrm.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Tazkera - c:\program files\Tazkera\Run.exe
HKCU-Run-MSMSGS - c:\program files\Messenger\msmsgs.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-12-18 02:39
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{05728846-c756-411d-ad39-f8063cd55b4b}]
@Denied: (Full) (Everyone)
"Model"=dword:000000fe
"Therad"=dword:0000000f
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):34,fd,11,81,e9,5b,aa,43,a2,7a,20,64,31,07,77,06,dc,3c,0a,f4,d3,
87,60,e7,b3,dc,c4,ff,b4,1a,59,e0,10,78,08,ec,72,2a,0d,77,00,00,00,00,00,00,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\RunDll32.exe
c:\windows\system32\wdfmgr.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\Internet Download Manager\IEMonitor.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-12-18 02:41:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-18 00:41
Pre-Run: 2,510,282,752 bytes free
Post-Run: 2,523,807,744 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 2C71BDBEFF06E0E88D3684D29AA5C1AF