ComboFix 08-09-05.12 - Administrator 09/10/2008 2:46:07.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.1370 [GMT 3:00]
Running from: C:\Downloads\Software\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-08-09 to 2008-09-09 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-10 00:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-10 00:00 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Free Download Manager
2008-09-09 23:59 360,480 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-09 23:59 2,312 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-09 21:40 17,232 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-09 21:40 1,799,200 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-09 12:49 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-09-09 12:45 5,124 ----a-w C:\Program Files\Fusion.ini
2008-09-09 11:51 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia Multimedia Player
2008-09-08 15:12 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-09-08 13:54 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-09-08 13:53 --------- d-----w C:\Program Files\Kaspersky Lab
2008-09-08 13:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-07 23:45 --------- d-----w C:\Documents and Settings\Administrator\Application Data\PC Suite
2008-09-07 23:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-09-07 23:04 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia
2008-09-07 23:02 --------- d-----w C:\Program Files\Nokia
2008-09-07 23:02 --------- d-----w C:\Program Files\DIFX
2008-09-07 23:02 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-09-07 23:02 --------- d-----w C:\Program Files\Common Files\Nokia
2008-09-07 23:01 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-09-07 22:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-09-06 19:16 22 ----a-w C:\Documents and Settings\Administrator\catchme.zip
2008-09-06 09:54 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ZoomBrowser EX
2008-09-06 09:54 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CameraWindowDC
2008-09-04 14:07 0 ----a-w C:\osy3.sys
2008-09-03 08:36 --------- d-----w C:\Program Files\Hotspot_Shield
2008-09-03 07:24 --------- d-----w C:\Program Files\برنامج عمل التأثيرات المائيه
2008-09-02 13:03 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Sonic
2008-08-31 22:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-31 15:46 --------- d-----w C:\Program Files\Akram
2008-08-31 14:02 --------- d-----w C:\Program Files\Google
2008-08-30 22:17 --------- d-----w C:\Documents and Settings\Administrator\Application Data\iComment
2008-08-30 20:15 --------- d-----w C:\Program Files\aMSN
2008-08-30 10:16 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-08-30 10:16 --------- d-----w C:\Program Files\JetAudio
2008-08-30 10:16 --------- d-----w C:\Program Files\Free Download Manager
2008-08-30 10:16 --------- d-----w C:\Program Files\ClocX
2008-08-30 10:16 --------- d-----w C:\Program Files\ALLCapture 2.0 Trial
2008-08-28 09:59 --------- d-----w C:\Program Files\Pcsx2
2008-08-26 19:09 --------- d-----w C:\Program Files\Wondershare
2008-08-26 11:19 --------- d-----w C:\Program Files\AnyReader
2008-08-26 09:33 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ALLCapture
2008-08-25 21:22 --------- d-----w C:\Program Files\Quranzu1
2008-08-25 08:44 --------- d-----w C:\Program Files\MSXML 4.0
2008-08-24 13:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2008-08-24 13:02 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Ulead Systems
2008-08-24 11:07 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-08-24 11:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-08-24 10:21 --------- d-----w C:\Program Files\SmartSound Software
2008-08-24 10:19 --------- d-----w C:\Program Files\QuickTime
2008-08-24 10:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-24 10:17 --------- d-----w C:\Program Files\Common Files\InterVideo
2008-08-24 10:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\InterVideo
2008-08-24 10:16 --------- d-----w C:\Program Files\Windows Media Components
2008-08-24 10:16 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2008-08-24 10:14 --------- d-----w C:\Program Files\Ulead Systems
2008-08-24 10:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
2008-08-24 07:07 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CANON INC
2008-08-23 23:17 --------- d-----w C:\Program Files\Common Files\Ahead
2008-08-23 23:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-08-22 12:16 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-08-22 12:14 --------- d-----w C:\Program Files\Microsoft.NET
2008-08-21 23:14 --------- d-----w C:\Program Files\Magic Swf2Avi 2008
2008-08-21 09:45 --------- d-----w C:\Program Files\Canon
2008-08-21 09:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-08-21 09:42 --------- d-----w C:\Program Files\Common Files\Canon
2008-08-20 21:20 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-08-20 21:19 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-08-20 21:19 172,032 ------w C:\WINDOWS\Setup1.exe
2008-08-20 20:43 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ErrorSweeper
2008-08-20 20:17 --------- d-----w C:\Program Files\SoftwareDoctor
2008-08-20 19:50 --------- d-----w C:\Program Files\Auslogics
2008-08-20 19:50 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Auslogics
2008-08-20 19:41 --------- d-----w C:\Program Files\Data Doctor Recovery Pen Drive
2008-08-20 08:32 --------- d-----w C:\Program Files\AskTBar
2008-08-20 00:21 6,112 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-08-20 00:21 52,637 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-08-20 00:11 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Ahead
2008-08-20 00:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-08-20 00:08 --------- d-----w C:\Program Files\Nero
2008-08-20 00:01 --------- d-----w C:\Program Files\Ahead
2008-08-19 22:42 --------- d-----w C:\Program Files\MSN Messenger
2008-08-19 19:50 --------- d-----w C:\Program Files\Mobily Connect Card
2008-08-19 17:40 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Protector Suite
2008-08-19 17:32 --------- d-----w C:\Program Files\DesktopDialer
2008-08-19 17:31 --------- d-----w C:\Program Files\Toshiba
2008-08-19 17:29 --------- d-----w C:\Program Files\DataLode
2008-08-19 17:28 --------- d-----w C:\Documents and Settings\Administrator\Application Data\toshiba
2008-08-19 17:21 --------- d-----w C:\Program Files\Protector Suite QL
2008-08-19 17:21 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-19 17:21 --------- d-----w C:\Program Files\Common Files\Protector Suite QL
2008-08-19 17:19 15,360 ----a-w C:\WINDOWS\system32\drivers\tdcmdpst.sys
2008-08-19 17:03 --------- d-----w C:\Program Files\DVD-RAM
2008-08-19 15:33 --------- d-----w C:\Program Files\ltmoh
2008-08-19 15:32 --------- d-----w C:\Program Files\Sonic
2008-08-19 15:25 --------- d-----w C:\Program Files\Realtek
2008-08-19 12:07 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Infineon
2008-08-19 11:28 --------- d-----w C:\Program Files\Picasa2
2008-08-19 11:15 --------- d-----w C:\Program Files\Western Digital Technologies
.
------- Sigcheck -------
01/27/2006 05:45 PM 576512 c287c8218dac8ee3aef1fb2018064699 C:\WINDOWS\system32\user32.dll
01/27/2006 11:09 PM 2016768 6df3bb5474a0e4b4ed0c546f0279b15a C:\WINDOWS\system32\ntkrnlpa.exe
01/27/2006 05:45 PM 2137088 8dc4d95c973170b2236c179e3c7f35a3 C:\WINDOWS\system32\ntoskrnl.exe
08/04/2004 12:56 AM 973312 a10b8a9309fee2bf9ee6538693844d77 C:\WINDOWS\explorer.exe
01/27/2006 11:01 PM 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\system32\spoolsv.exe
.
(((((((((((((((((((((((((((((
snapshot@Sat 09-06-2008_14.47.59.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-09-16 00:02:34 221,488 -c----w C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe
+ 2006-09-16 00:02:36 379,184 -c----w C:\WINDOWS\$NtUninstallWudf01005$\spuninst\updspapi.dll
+ 2006-09-15 19:30:12 70,656 -c----w C:\WINDOWS\$NtUninstallWudf01005$\spuninst\WudfCustom.dll
+ 2006-09-28 17:13:26 95,344 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfcoinstaller.dll
+ 2006-09-28 15:56:38 146,432 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfhost.exe
+ 2006-09-28 15:55:50 77,568 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfpf.sys
+ 2006-09-28 15:56:16 165,376 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfplatform.dll
+ 2006-09-28 16:00:34 82,944 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfrd.sys
+ 2006-09-28 15:56:14 55,808 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfsvc.dll
+ 2006-09-28 15:56:38 316,416 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfx.dll
+ 2008-09-09 12:49:10 7,778 ----a-w C:\WINDOWS\Fonts\irunin.dat
+ 2008-09-07 23:02:00 10,134 ----a-r C:\WINDOWS\Installer\{73284F36-E17E-44B0-85E2-F0336A6E749F}\ARPPRODUCTICON.exe
+ 2008-09-07 23:01:41 3,262 ----a-r C:\WINDOWS\Installer\{74C5EA04-AF1E-45B2-949B-4841EE949C40}\ARPPRODUCTICON.exe
+ 2008-09-07 23:02:56 15,086 ----a-r C:\WINDOWS\Installer\{FCD8DCE6-94C8-4FF6-8E3E-D3C96A5A707E}\ARPPRODUCTICON.exe
+ 2007-03-29 19:00:40 203,264 ----a-r C:\WINDOWS\system32\CddbCdda.dll
- 2008-09-06 11:36:50 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\s\index.dat
+ 2008-09-08 15:38:10 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\s\index.dat
- 2008-08-31 22:07:36 752,576 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
+ 2008-09-09 23:58:48 758,864 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
- 2008-09-06 11:36:50 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-08 15:38:10 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2006-01-27 20:01:30 207,360 ----a-w C:\WINDOWS\system32\drivers\Dot4.sys
+ 2006-01-27 20:00:44 12,928 ----a-w C:\WINDOWS\system32\drivers\Dot4Prt.sys
+ 2006-01-27 20:00:44 8,704 ----a-w C:\WINDOWS\system32\drivers\Dot4scan.sys
+ 2006-01-27 20:00:44 23,808 ----a-w C:\WINDOWS\system32\drivers\Dot4usb.sys
- 2008-08-20 13:56:15 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
+ 2008-07-21 15:34:36 121,872 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
+ 2008-01-29 15:29:38 32,784 ----a-w C:\WINDOWS\system32\drivers\klbg.sys
+ 2008-03-13 16:02:46 26,640 ----a-w C:\WINDOWS\system32\drivers\klfltdev.sys
- 2007-12-28 16:51:04 195,344 ----a-w C:\WINDOWS\system32\drivers\klif.sys
+ 2008-09-08 13:53:38 213,008 ----a-w C:\WINDOWS\system32\drivers\klif.sys
- 2007-12-13 10:28:40 24,592 ----a-w C:\WINDOWS\system32\drivers\klim5.sys
+ 2008-04-30 15:06:48 24,592 ----a-w C:\WINDOWS\system32\drivers\klim5.sys
- 2008-02-08 15:35:42 23,604 ----a-w C:\WINDOWS\system32\drivers\klopp.dat
+ 2008-07-29 17:20:00 24,774 ----a-w C:\WINDOWS\system32\drivers\klopp.dat
+ 2007-11-06 06:26:20 535,040 ----a-w C:\WINDOWS\system32\drivers\UMDF\PCCSWpdDriver.dll
- 2006-09-28 15:55:50 77,568 ------w C:\WINDOWS\system32\drivers\WudfPf.sys
+ 2006-09-15 19:29:52 76,544 ------w C:\WINDOWS\system32\drivers\WudfPf.sys
- 2006-09-28 16:00:34 82,944 ------w C:\WINDOWS\system32\drivers\WudfRd.sys
+ 2006-09-15 19:30:10 82,688 ------w C:\WINDOWS\system32\drivers\WudfRd.sys
+ 2007-02-22 07:15:56 137,216 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcd_94ED21C3518B61A99B9C275108271E1F73A0EB8A\nmwcd.sys
+ 2007-02-22 07:15:12 90,624 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcd_94ED21C3518B61A99B9C275108271E1F73A0EB8A\nmwcdcls.dll
+ 2007-02-22 07:15:12 65,536 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcd_94ED21C3518B61A99B9C275108271E1F73A0EB8A\nmwcdcocls.dll
+ 2007-02-22 07:15:14 8,320 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcdc_94ED21C3518B61A99B9C275108271E1F73A0EB8A\nmwcdc.sys
+ 2007-02-22 07:15:14 12,288 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcdcj_94ED21C3518B61A99B9C275108271E1F73A0EB8A\nmwcdcj.sys
+ 2007-02-22 07:15:14 12,288 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcdm2k_94ED21C3518B61A99B9C275108271E1F73A0EB8A\nmwcdcm.sys
+ 2007-11-06 06:26:20 535,040 -c--a-w C:\WINDOWS\system32\DRVSTORE\pccswpddri_4B5D882780830B9245673D197146B7FF82A23CFB\PCCSWpdDriver.dll
+ 2007-11-06 06:20:02 831,048 -c--a-w C:\WINDOWS\system32\DRVSTORE\pccswpddri_4B5D882780830B9245673D197146B7FF82A23CFB\WudfUpdate_01005.dll
- 2008-08-31 22:06:39 1,779,568 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-09-09 23:56:57 1,792,304 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2006-01-27 20:00:58 324,608 ----a-w C:\WINDOWS\system32\hpojwia.dll
- 2008-02-08 15:37:44 219,664 ----a-w C:\WINDOWS\system32\klogon.dll
+ 2008-07-29 17:21:42 218,376 ----a-w C:\WINDOWS\system32\klogon.dll
+ 2007-02-22 07:15:12 90,624 ----a-w C:\WINDOWS\system32\nmwcdcls.dll
- 2008-09-06 11:41:12 58,920 ----a-w C:\WINDOWS\system32\perfc001.dat
+ 2008-09-09 09:58:09 58,920 ----a-w C:\WINDOWS\system32\perfc001.dat
- 2008-09-06 11:41:12 58,930 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-09-09 09:58:09 58,930 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-09-06 11:41:12 328,690 ----a-w C:\WINDOWS\system32\perfh001.dat
+ 2008-09-09 09:58:09 328,690 ----a-w C:\WINDOWS\system32\perfh001.dat
- 2008-09-06 11:41:12 392,630 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-09-09 09:58:09 392,630 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2006-01-27 20:00:56 435,200 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPF900AL.DLL
+ 2006-01-27 20:00:56 1,853,952 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPFIMG50.DLL
+ 2006-01-27 20:01:28 87,552 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPFUD50.DLL
+ 2006-01-27 20:00:56 32,768 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPFUI50.DLL
+ 2006-01-27 20:01:30 264,704 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIDRV.DLL
+ 2006-01-27 20:01:30 196,608 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIDRVUI.DLL
+ 2006-01-27 20:01:32 619,520 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIRES.DLL
- 2006-09-25 14:58:48 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2006-09-16 00:02:34 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe
- 2006-09-28 17:13:26 95,344 ------w C:\WINDOWS\system32\WUDFCoinstaller.dll
+ 2006-09-15 20:30:16 87,040 ------w C:\WINDOWS\system32\WUDFCoinstaller.dll
- 2006-09-28 15:56:38 146,432 ------w C:\WINDOWS\system32\WudfHost.exe
+ 2006-09-15 20:30:06 142,848 ------w C:\WINDOWS\system32\WudfHost.exe
- 2006-09-28 15:56:16 165,376 ------w C:\WINDOWS\system32\WudfPlatform.dll
+ 2006-09-15 19:29:54 163,840 ------w C:\WINDOWS\system32\WudfPlatform.dll
- 2006-09-28 15:56:14 55,808 ------w C:\WINDOWS\system32\WudfSvc.dll
+ 2006-09-15 20:30:16 55,296 ------w C:\WINDOWS\system32\WudfSvc.dll
+ 2007-11-06 06:20:02 831,048 ----a-w C:\WINDOWS\system32\WudfUpdate_01005.dll
- 2006-09-28 15:56:38 316,416 ------w C:\WINDOWS\system32\WUDFx.dll
+ 2006-09-15 20:30:16 308,224 ------w C:\WINDOWS\system32\WUDFx.dll
+ 2008-09-10 00:01:32 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_710.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HUAWEI 3G Data Card MTS"="C:\Program Files\Mobily Connect Card\Mobily Connect Card.exe" [03/31/2007 11:58 AM 335872]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [01/19/2007 12:55 PM 5674352]
"Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" [09/18/2007 11:35 PM 2445359]
"Free Upload Manager"="C:\Program Files\Free Download Manager\fum\fum.exe" [07/29/2007 08:13 PM 253952]
"Free Uploader Oe Integration"="C:\Program Files\Free Download Manager\FUM\fumoei.exe" [06/10/2007 07:02 PM 40960]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [11/09/2007 01:16 PM 688128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [03/23/2004 10:40 PM 196608]
"ClocX"="C:\Program Files\ClocX\ClocX.exe" [04/13/2004 05:12 PM 103936]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [08/19/2008 01:16 PM 180269]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 01:06 PM 40048]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [03/23/2006 01:17 PM 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [03/23/2006 01:13 PM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [03/23/2006 01:17 PM 118784]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [10/28/2005 09:08 PM 335872]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [12/16/2005 02:41 AM 188416]
"00THotkey"="C:\WINDOWS\system32\
00THotkey.exe" [04/24/2006 06:09 PM 253952]
"DpUtil"="C:\Program Files\TOSHIBA\DualPointUtility\TEDTray.exe" [06/28/2005 08:11 PM 155648]
"PSQLLauncher"="C:\Program Files\Protector Suite QL\launcher.exe" [05/05/2006 05:36 PM 30208]
"TMESRV.EXE"="C:\Program Files\TOSHIBA\TME3\TMESRV31.EXE" [12/14/2005 12:00 PM 126976]
"TMERzCtl.EXE"="C:\Program Files\TOSHIBA\TME3\TMERzCtl.EXE" [02/22/2006 05:41 PM 86016]
"PINGER"="C:\TOSHIBA\IVP\ISM\pinger.exe" [03/17/2005 05:37 PM 151552]
"TosHKCW.exe"="C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [05/17/2005 11:42 AM 49152]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [04/26/2005 04:13 PM 122880]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [03/01/2007 03:57 PM 153136]
"UVS11 Preload"="C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe" [03/03/2007 02:12 PM 341488]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [09/01/2006 03:57 PM 282624]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [11/10/2005 01:03 PM 36975]
"IVPServiceMgr"="C:\TOSHIBA\IVP\ISM\ivpsvmgr.exe" [10/20/2003 09:37 AM 475136]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [07/29/2008 08:20 PM 206088]
"RTHDCPL"="RTHDCPL.EXE" [05/09/2006 01:53 PM 16207360 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [04/24/2006 03:20 PM 1448960 C:\WINDOWS\SkyTel.exe]
"AGRSMMSG"="AGRSMMSG.exe" [06/30/2006 05:32 AM 89541 C:\WINDOWS\agrsmmsg.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [11/07/2007 05:35 PM 1294336]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"nlhr"="C:\WINDOWS\System32\AdvPack.Dll" [08/04/2004 12:55 AM 99840]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [08/03/2004 10:59 PM 44544]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
08/19/2005 03:28 PM 389120 C:\WINDOWS\system32\IfxWlxEN.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
05/05/2006 05:48 PM 40448 C:\WINDOWS\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"=
"C:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe"=
"C:\\Program Files\\Mobily Connect Card\\Mobily Connect Card.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\WINDOWS\system32\DRIVERS\thpdrv.sys [12/27/2004 11:31 PM 16384]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\WINDOWS\system32\DRIVERS\Thpevm.SYS [11/13/2004 12:24 PM 6144]
R1 PersonalSecureDrive;PersonalSecureDrive;C:\WINDOWS\system32\drivers\psd.sys [09/29/2005 02:15 PM 35488]
R1 TMEI3E;TMEI3E;C:\WINDOWS\system32\Drivers\TMEI3E.SYS [06/16/2004 11:08 AM 5888]
R2 FdRedir;FdRedir;C:\Program Files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [05/05/2006 06:00 PM 13568]
R2 FileDisk2;FileDisk Protector Kernel Driver;C:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys [05/05/2006 05:59 PM 33024]
R2 smihlp;SMI helper driver;C:\Program Files\Protector Suite QL\smihlp.sys [05/05/2006 05:33 PM 3456]
R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [06/10/2005 01:26 PM 35968]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/30/2008 06:06 PM 24592]
S3 HWACCESS;HWACCESS;C:\WINDOWS\SYSTEM32\HWACCESS.SYS [08/19/2008 01:25 PM 6808]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{02121155-7ddb-11dd-9969-0019d26fd998}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6e7a6706-6e25-11dd-a77e-00037aee8bb2}]
\Shell\AutoRun\command - G:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6e7a670a-6e25-11dd-a77e-00037aee8bb2}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b3bf8d3f-774e-11dd-a790-00037aee8bb2}]
\Shell\AutoRun\command - G:\AutoRun.exe
.
s of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.kya9.net/vb/index.php
R0 -: HKLM-Main,Start Page = about:blank
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 -: Free Download Manager تحميل الفيديو بواسطة -
Files\Free Download Manager\dlfvideo.htm
O8 -: تحميل المحددة بفري داونلود مانيجر -
Files\Free Download Manager\dlselected.htm
O8 -: تنزيل الكل بفري داونلود مانيجر -
Files\Free Download Manager\dlall.htm
O8 -: تنزيل بفري داونلود مانيجر -
Files\Free Download Manager\dllink.htm
O17 -: HKLM\CCS\Interface\{7DF70AED-2ABE-40A4-8FD5-11F90B3270B7}: NameServer = 10.6.9.12 10.6.9.11
.
.
------- File Associations (Beta) -------
.
txtfile=NOTEPAD %1
vbefile\shell\edit\command=C:\WINDOWS\Notepad.exe %1
vbsfile\shell\edit\command=C:\WINDOWS\Notepad.exe %1
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-10 02:59:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\IFXTCS.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\IFXSPMGT.exe
C:\Program Files\Infineon\Security Platform Software\PSDsrvc.EXE
C:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\system32\ThpSrv.exe
C:\WINDOWS\system32\TODDSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Infineon\Security Platform Software\PSDrt.exe
C:\Program Files\Infineon\Security Platform Software\SpTNA.exe
C:\Program Files\Apoint2K\ApntEx.exe
C:\Program Files\Toshiba\TME3\TMEEJME.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe
C:\WINDOWS\system32\igfxsrvc.exe
.
**************************************************************************
.
Completion time: 09/10/2008 3:04:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-10 00:04:09
ComboFix2.txt 2008-09-06 12:23:00
ComboFix3.txt 2008-09-06 11:49:37
Pre-Run: 46,905,704,448 bytes free
Post-Run: 46,982,340,608 bytes free
394 --- E O F --- 2008-08-26 00:00:43