ComboFix 09-04-01.01 - TOHIBA 04/02/2009 22:05:05.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.1023.640 [GMT 3:00]
Running from: c:\documents and settings\TOHIBA\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *enabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
c:\windows\system32\cmnocfg.xml
c:\windows\system32\dumphive.exe
c:\windows\system32\Process.exe
c:\windows\system32\qviexio3.dat
c:\windows\system32\SrchSTS.exe
c:\windows\system32\sys_dll.dll
c:\windows\system32\tmp.reg
c:\windows\system32\Ultra.dll
c:\windows\system32\VCCLSID.exe
c:\windows\system32\winio.vxd
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2009-03-02 to 2009-04-02 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-02 18:17 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-26 22:17 --------- d-----w c:\program files\GetData
2009-03-26 22:11 --------- d-----w c:\program files\Google
2009-03-26 22:11 --------- d-----w c:\program files\ElcomSoft
2009-03-26 22:11 --------- d-----w c:\program files\Common Files\xing shared
2009-03-26 22:11 --------- d-----w c:\program files\Common Files\Real
2009-03-26 22:09 --------- d-----w c:\program files\FTP Commander Deluxe
2009-03-26 21:07 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-26 15:28 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-12 22:28 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-03-12 22:28 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2003-08-27 21:19 36,963 ----a-r c:\program files\Common Files\SM1updtr.dll
2008-12-09 00:31 48,584,736 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-09 00:27 1,087,520 --sha-w c:\windows\system32\drivers\fidbox2.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
11/28/2008 12:00 AM 204248 --a------ c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [06/12/2007 04:16 AM 4670968]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [09/05/2003 01:24 PM 65536]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/14/2008 03:12 AM 15360]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [02/11/2005 03:00 AM 1937408]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil9f.exe" [03/25/2008 05:32 AM 218496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [09/03/2004 07:25 PM 73728]
"TouchED"="c:\program files\TOSHIBA\TouchED\TouchED.Exe" [01/22/2003 04:00 AM 126976]
"TosHKCW.exe"="c:\program files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [09/10/2002 01:07 AM 49152]
"TOSHIBA Picture Enhancement Utility"="c:\program files\TOSHIBA\TOSHIBA Picture Enhancement Utility\TosPEHK.exe" [08/18/2004 02:51 AM 638976]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [04/01/2004 08:52 PM 1368064]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [03/02/2004 11:45 PM 135168]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [10/20/2003 07:39 PM 159744]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [06/30/2004 04:04 AM 1077326]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [09/01/2004 08:12 PM 4554752]
"Notebook Maximizer"="c:\program files\Notebook Maximizer\maximizer_startup.exe" [05/26/2004 12:35 AM 28672]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [07/09/2001 08:50 PM 155648]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [09/27/2003 01:43 AM 184320]
"ehTray"="c:\windows\ehome\ehtray.exe" [08/10/2004 02:04 PM 59392]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [03/24/2004 08:40 AM 196608]
"00THotkey"="c:\windows\system32\
00THotkey.exe" [06/29/2004 03:24 AM 258048]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [09/21/2004 07:25 PM 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM 144784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [03/26/2009 05:08 PM 198160]
"TPSMain"="TPSMain.exe" [08/27/2004 07:34 PM 278528 c:\windows\system32\TPSMain.exe]
"TFNF5"="TFNF5.exe" [06/28/2004 08:16 PM 73728 c:\windows\system32\TFNF5.exe]
"TFncKy"="TFncKy.exe" [BU]
"nwiz"="nwiz.exe" [09/01/2004 08:12 PM 921600 c:\windows\system32\nwiz.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
"AGRSMMSG"="AGRSMMSG.exe" [02/21/2004 01:00 AM 88363 c:\windows\agrsmmsg.exe]
"CFSServ.exe"="CFSServ.exe" [BU]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-09-22 113664]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2004-06-17 380928]
PalStart.lnk - c:\program files\Paltalk Messenger\palstart.exe [2007-05-25 45568]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2004-09-20 155648]
§ک ں颬نïé ںé«©ïم é• Microsoft Office OneNote 2003.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-04-19 64864]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\unzipped\\BitComet_0.61\\BitComet_Win9x.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.321\\English\\setup.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\English\\setup.exe"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 7.0\\avp.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\FTP Commander Deluxe\\cFTPdeluxe.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:*

isabled

oVoo TCP المنفذ 443
"443:UDP"= 443:UDP:*

isabled

oVoo UDP المنفذ 443
"37674:TCP"= 37674:TCP:*

isabled

oVoo TCP المنفذ 37674
"37674:UDP"= 37674:UDP:*

isabled

oVoo UDP المنفذ 37674
"37675:UDP"= 37675:UDP:*

isabled

oVoo UDP المنفذ 37675
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2007-12-13 24592]
S2 mrtRate;mrtRate; [x]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\DRIVERS\br3gmdm.sys --> c:\windows\system32\DRIVERS\br3gmdm.sys [?]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [2007-10-12 23552]
S3 ttv200x;TOSHIBA PCI TV Tuner type W;c:\windows\system32\drivers\ttv200x.sys [2004-09-08 822656]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Adware Agent - c:\documents and settings\TOHIBA\My Documents\عبدالعزيز\Adware Agent\Adware Agent.exe
HKLM-Run-Ad-Watch - c:\program files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Settings,ProxyOverride = local
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
FF - ProfilePath - c:\documents and settings\TOHIBA\Application Data\Mozilla\Firefox\Profiles\xbmfv9vs.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sa/
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-02 22:18:56
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{32302C32-E444-615E-7E2A-DA5DD46CAABA}\InProcServer32*]
"jaajmgecgpdhfafgcbni"=hex:6a,61,64,6f,65,67,63,6c,70,6e,70,6d,64,64,65,70,64,
6c,64,63,00,00
"iaajggkbbnndakfeca"=hex:6a,61,64,6f,65,67,63,6c,70,6e,70,6d,64,64,65,70,64,6c,
64,63,00,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1532)
c:\windows\system32\klogon.dll
.
Completion time: 04/02/2009 22:23:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-02 19:22:00
Pre-Run: 53,832,732,672 bytes free
Post-Run: 54,353,551,360 bytes free
170 --- E O F --- 2008-11-13 10:05:19