تقرير الهايجاك الجديد بعد استخدام الأداة ..
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:25:13 AM, on 2/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Documents and Settings\tazebama.dl_
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\Toshiba Applet\TMEPROP.exe
C:\Program Files\Toshiba\Toshiba Applet\DockMsgFrom.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\system32\bv2.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\tme3srv.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Toshiba\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TMEPROP] C:\Program Files\Toshiba\Toshiba Applet\TMEPROP.exe -S
O4 - HKLM\..\Run: [DockMsgFrom] C:\Program Files\Toshiba\Toshiba Applet\DockMsgFrom.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [iemultjx] C:\WINDOWS\system32\iemultjx.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [bv2] C:\WINDOWS\system32\bv2.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [comp eggs] C:\DOCUME~1\Toshiba\APPLIC~1\BALLAB~1\type mp3.exe
O4 - HKCU\..\Run: [12CFG914-K641-26SF-N32P] C:\RECYCLER\S-1-5-21-0243336031-4052116379-881863308-0851\vse432.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: E?E - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: TME3SRV - IEC - C:\Program Files\TOSHIBA\TOSHIBA Applet\tme3srv.exe
--
End of file - 9830 bytes
====================
تقرير الأداة ..
ComboFix 09-01-07.02 - Toshiba 2009-02-28 6:09:18.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.503.173 [GMT -8:00]
Running from: c:\documents and settings\Toshiba\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated)
FW: Kaspersky Internet Security *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\cfxer.exe
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
c:\windows\winsystem.exe
C:\zPharaoh.exe
.
((((((((((((((((((((((((( Files Created from 2009-01-28 to 2009-02-28 )))))))))))))))))))))))))))))))
.
2009-02-28 06:15 . 2009-02-28 06:17 154,991 -r-hs---- C:\zPharaoh.exe
2009-02-28 06:15 . 2009-02-28 06:17 126 -r-hs---- C:\autorun.inf
2009-02-28 06:00 . 2009-02-28 06:00 8,552 --a------ c:\documents and settings\Toshiba\bv2.exe
2009-02-28 04:21 . 2009-02-28 04:21 96,976 --a------ c:\windows\system32\drivers\klin.dat
2009-02-28 04:21 . 2009-02-28 04:21 87,855 --a------ c:\windows\system32\drivers\klick.dat
2009-02-28 04:20 . 2009-02-28 06:01 37,788 --a------ c:\documents and settings\Toshiba\iemultjx.exe
2009-02-28 04:14 . 2009-02-28 04:14 <DIR> d-------- c:\program files\Kaspersky Lab
2009-02-28 04:14 . 2009-02-28 06:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-02-28 04:14 . 2009-02-28 06:12 627,232 --ahs---- c:\windows\system32\drivers\fidbox.dat
2009-02-28 04:14 . 2009-02-28 06:12 286,752 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2009-02-28 04:14 . 2009-02-28 06:12 5,980 --ahs---- c:\windows\system32\drivers\fidbox.idx
2009-02-28 04:14 . 2009-02-28 06:12 2,060 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2009-02-28 04:05 . 2009-02-28 04:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-02-28 03:53 . 2009-02-28 04:55 <DIR> d-------- c:\windows\system32\CatRoot_bak
2009-02-28 03:28 . 2009-02-28 03:28 37,788 --a------ c:\windows\system32\iemultjx.exe
2009-02-28 03:27 . 2009-02-28 06:00 33,924 --a------ c:\documents and settings\Toshiba\cmgrs.exe
2009-02-28 03:00 . 2005-02-24 19:35 22,752 --a------ c:\windows\system32\spupdsvc.exe
2009-02-28 02:18 . 2009-02-28 06:14 154,751 --a------ c:\documents and settings\tazebama.dl_
2009-02-28 02:18 . 2009-02-28 06:17 154,751 --a------ c:\documents and settings\hook.dl_
2009-02-28 02:18 . 2009-02-28 05:30 37,788 --a------ c:\windows\system32\bv2.exe
2009-02-28 02:18 . 2009-02-28 06:15 32,768 --a------ c:\documents and settings\tazebama.dll
2009-02-27 12:18 . 2009-02-28 00:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\flag barb cake wipe
2009-02-27 12:17 . 2009-02-27 12:17 <DIR> d-------- c:\program files\ballaboutmix
2009-02-27 12:17 . 2009-02-27 12:19 <DIR> d-------- c:\documents and settings\Toshiba\Application Data\ballaboutmix
2009-02-27 12:16 . 2009-02-27 12:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-02-27 12:15 . 2009-02-27 12:15 <DIR> d-------- c:\program files\Windows Live
2009-02-27 12:15 . 2009-02-27 12:15 <DIR> d-------- c:\program files\Circle Developement
2009-02-27 12:14 . 2009-02-27 13:44 <DIR> d-------- c:\program files\Messenger Plus! Live
2009-02-27 11:58 . 2009-02-27 11:58 <DIR> d-------- c:\documents and settings\Toshiba\Application Data\Thinstall
2009-02-26 14:07 . 2004-08-03 23:10 274,304 --a------ c:\windows\system32\drivers\bthport.sys
2009-02-26 14:07 . 2004-08-03 23:10 274,304 --a--c--- c:\windows\system32\dllcache\bthport.sys
2009-02-26 14:07 . 2004-08-03 22:58 100,992 --a------ c:\windows\system32\drivers\bthpan.sys
2009-02-26 14:07 . 2004-08-03 22:58 100,992 --a--c--- c:\windows\system32\dllcache\bthpan.sys
2009-02-26 14:07 . 2004-08-03 23:10 59,648 --a------ c:\windows\system32\drivers\rfcomm.sys
2009-02-26 14:07 . 2004-08-03 23:10 59,648 --a--c--- c:\windows\system32\dllcache\rfcomm.sys
2009-02-26 14:07 . 2004-08-03 23:10 18,944 --a------ c:\windows\system32\drivers\BTHUSB.SYS
2009-02-26 14:07 . 2004-08-03 23:10 18,944 --a--c--- c:\windows\system32\dllcache\bthusb.sys
2009-02-26 14:07 . 2004-08-03 23:10 17,024 --a------ c:\windows\system32\drivers\BthEnum.sys
2009-02-26 14:07 . 2004-08-03 23:10 17,024 --a--c--- c:\windows\system32\dllcache\bthenum.sys
2009-02-26 05:36 . 2009-02-28 06:00 19,456 --a------ c:\documents and settings\Toshiba\tvs2.exe
2009-02-26 05:11 . 2009-02-26 05:11 <DIR> d-------- c:\documents and settings\Toshiba\Application Data\GRETECH
2009-02-26 04:35 . 2009-02-26 04:35 <DIR> d-------- c:\documents and settings\MyDocuments
2009-02-26 04:35 . 2009-02-26 04:35 273 --a------ c:\documents and settings\MyDocuments.rar
2009-02-26 04:35 . 2009-02-26 04:35 0 --a------ c:\documents and settings\MyDocuments\readthis.doc.exe
2009-02-26 04:35 . 2009-02-26 04:35 0 --a------ c:\documents and settings\MyDocuments\Readme.doc .exe
2009-02-26 04:34 . 2009-02-26 05:37 <DIR> d-------- c:\documents and settings\Toshiba\Application Data\tazebama
2009-02-26 04:11 . 2009-02-28 05:08 9,216 --a------ C:\sce.exe
2009-02-26 02:57 . 2004-08-04 00:56 159,232 --a------ c:\windows\system32\ptpusd.dll
2009-02-26 02:57 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-02-26 02:57 . 2004-08-03 22:58 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2009-02-26 02:57 . 2001-08-17 22:36 5,632 --a------ c:\windows\system32\ptpusb.dll
2009-02-26 02:53 . 2009-02-26 02:53 <DIR> d---s---- c:\documents and settings\Toshiba\UserData
2009-02-25 10:34 . 2009-02-25 10:34 <DIR> d-------- c:\documents and settings\Toshiba\Application Data\COWON
2009-02-25 09:03 . 2009-02-27 11:53 <DIR> d-------- c:\documents and settings\Toshiba\Contacts
2009-02-25 06:37 . 2009-02-25 06:37 268 --ah----- C:\sqmdata01.sqm
2009-02-25 06:37 . 2009-02-25 06:37 244 --ah----- C:\sqmnoopt01.sqm
2009-02-25 01:22 . 2009-02-25 01:22 268 --ah----- C:\sqmdata00.sqm
2009-02-25 01:22 . 2009-02-25 01:22 244 --ah----- C:\sqmnoopt00.sqm
2009-02-25 00:38 . 2009-02-25 00:38 <DIR> d----c--- c:\windows\system32\DRVSTORE
2009-02-25 00:38 . 2009-02-28 06:14 <DIR> d-------- c:\program files\MSN Messenger
2009-02-25 00:37 . 2009-02-25 00:37 <DIR> d-------- c:\program files\Common Files\xing shared
2009-02-25 00:35 . 2009-02-25 00:35 <DIR> d-------- c:\program files\Lavasoft
2009-02-25 00:35 . 2009-02-25 00:35 <DIR> d-------- c:\program files\GRETECH
2009-02-25 00:34 . 2009-02-25 10:35 <DIR> d-------- c:\program files\JetAudio
2009-02-24 23:56 . 2005-08-08 09:53 <DIR> d-------- c:\documents and settings\Toshiba\WINDOWS
2009-02-24 23:56 . 2005-08-08 10:29 <DIR> d-------- c:\documents and settings\Toshiba\Application Data\You've Got Pictures Screensaver
2009-02-24 23:56 . 2005-08-08 10:01 <DIR> d-------- c:\documents and settings\Toshiba\Application Data\toshiba
2009-02-24 23:56 . 2005-08-08 10:06 <DIR> d-------- c:\documents and settings\Toshiba\Application Data\InterTrust
2009-02-24 23:56 . 2009-02-24 23:56 <DIR> d-------- c:\documents and settings\Toshiba\Application Data\Intel
2009-02-24 23:56 . 2005-08-08 10:32 <DIR> d-------- c:\documents and settings\Toshiba\Application Data\AOL
2009-02-24 23:56 . 2009-02-28 06:12 <DIR> d-------- c:\documents and settings\Toshiba
2009-02-24 23:55 . 2005-08-08 09:53 <DIR> d-------- c:\windows\system32\config\systemprofile\WINDOWS
2009-02-24 23:55 . 2009-02-24 23:55 <DIR> d-------- c:\documents and settings\All Users\Application Data\Intel
2009-02-24 23:55 . 2009-02-24 23:55 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Intel
2009-02-24 23:55 . 2009-02-24 23:55 17,119 --a------ c:\windows\system32\drivers\AegisP.sys
2009-02-24 23:54 . 2005-08-08 09:53 <DIR> d-------- c:\documents and settings\Default User\WINDOWS
2009-02-24 23:54 . 2004-10-29 18:48 3,222,784 --a------ c:\windows\system32\drivers\w29n51.sys
2009-02-24 23:54 . 2004-10-15 10:20 1,654,784 --a------ c:\windows\system32\W29MLRES.DLL
2009-02-24 23:54 . 2004-10-15 10:20 458,752 --a------ c:\windows\system32\w29NCPA.dll
2009-02-24 23:54 . 2004-11-09 16:31 13 --a------ c:\windows\system32\drivers\verfile.tic
2009-02-24 23:44 . 2009-02-24 23:44 61 --a------ c:\windows\smscfg.ini
2009-02-24 23:43 . 2009-02-25 00:44 <DIR> d-------- c:\windows\SHELLNEW
2009-02-24 23:43 . 2009-02-24 23:43 <DIR> d-------- c:\program files\Microsoft.NET
2009-02-24 23:43 . 2009-02-24 23:43 <DIR> d-------- c:\program files\Microsoft ActiveSync
2009-02-24 23:43 . 2003-06-18 17:31 17,920 --a------ c:\windows\system32\mdimon.dll
2009-02-24 23:42 . 2009-02-24 23:42 <DIR> d-------- c:\program files\Microsoft Works
2009-02-24 23:41 . 2005-06-08 09:58 135,168 --a------ c:\windows\system32\igfxres.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-28 13:57 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-28 12:57 463,215 ----a-w c:\windows\IsUninst.exe
2009-02-28 12:57 440,175 ----a-w c:\windows\winhlp32.exe
2009-02-28 12:57 302,959 ----a-w c:\windows\regedit.exe
2009-02-28 12:57 254,887 ----a-w c:\windows\dla.exe
2009-02-28 12:57 246,639 ----a-w c:\windows\InstDrvr.exe
2009-02-28 12:57 221,039 ----a-w c:\windows\agrsmdel.exe
2009-02-28 12:57 21,123,497 ----a-w c:\windows\cfdemo.exe
2009-02-28 12:57 182,127 ----a-w c:\windows\twunk_32.exe
2009-02-28 10:19 242,543 ----a-w c:\windows\unvise32qt.exe
2009-02-25 08:37 --------- d-----w c:\program files\Real
2009-02-25 08:36 --------- d-----w c:\program files\Common Files\Real
2009-02-25 08:34 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-25 07:54 --------- d-----w c:\program files\Intel
2009-02-25 07:41 --------- d-----w c:\program files\InterVideo
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2009-02-28 222063]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2009-02-28 5830879]
"comp eggs"="c:\docume~1\Toshiba\APPLIC~1\BALLAB~1\type mp3.exe" [2009-02-28 734063]
"12CFG914-K641-26SF-N32P"="c:\recycler\S-1-5-21-0243336031-4052116379-881863308-0851\vse432.exe" [2009-02-28 8552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2005-08-10 356352]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-08 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-08 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-08 114688]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2009-02-28 184320]
"TMEPROP"="c:\program files\Toshiba\Toshiba Applet\TMEPROP.exe" [2005-07-22 253952]
"DockMsgFrom"="c:\program files\Toshiba\Toshiba Applet\DockMsgFrom.exe" [2004-11-11 114688]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2009-02-28 122880]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 151552]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2009-02-28 385024]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-25 185896]
"iemultjx"="c:\windows\system32\iemultjx.exe" [2009-02-28 37788]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-28 206088]
"bv2"="c:\windows\system32\bv2.exe" [2009-02-28 37788]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-12 c:\windows\agrsmmsg.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
"TFncKy"="TFncKy.exe" [BU]
"TPSMain"="TPSMain.exe" [2005-05-31 c:\windows\system32\TPSMain.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]
"CFSServ.exe"="CFSServ.exe" [BU]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2005-08-08 312175]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 11:27 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll,c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll,c:\progra~1\KASPER~1\KASPER~1\adialhk.dll,c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Z]
\Shell\AutoRun\command - Z:\INSTALL.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0378d82b-035e-11de-b1e2-00038a000015}]
\Shell\AutoRun\command - E:\zPharaoh.exe
\Shell\explore\command - E:\zPharaoh.exe
\Shell\open\command - E:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0378d839-035e-11de-b1e2-00038a000015}]
\Shell\AutoRun\command - G:\zPharaoh.exe
\Shell\explore\command - G:\zPharaoh.exe
\Shell\open\command - G:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0378d853-035e-11de-b1e2-00038a000015}]
\Shell\AutoRun\command - e:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\cfxer.exe
\Shell\open\command - e:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\cfxer.exe
.
*******s of the 'Scheduled Tasks' folder
2009-02-28 c:\windows\Tasks\B41917BB912EB7FF.job
- c:\docume~1\toshiba\applic~1\ballab~1\Lovepuresign.exe [2009-02-28 02:25]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Tvs - c:\program files\Toshiba\Tvs\TvsTray.exe
HKLM-Run-PadTouch - c:\program files\TOSHIBA\Touch and Launch\PadExe.exe
HKLM-Run-Windows API Control Center - winsystem.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-02-28 06:16:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\cmd.exe.tmp 545135 bytes executable
c:\windows\system32\bv2.log 65 bytes
scan completed successfully
hidden files: 2
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1692)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\documents and settings\tazebama.dl_
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\rundll32.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
c:\windows\system32\TPSBattM.exe
c:\program files\TOSHIBA\TOSHIBA Applet\tme3srv.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-02-28 6:20:00 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-28 14:19:56
Pre-Run: 146,236,395,520 bytes free
Post-Run: 146,876,149,760 bytes free
268 --- E O F --- 2009-02-28 11:00:49