الله يغليك يالغلا
وأكرر شكري على تجاوبك السريع معي
وسويت اللي قلت عنه
وهذا التقرير
ComboFix 09-05-02.4 - UserXP 05/02/2009 23:01.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.2039.1487 [GMT 3:00]
Running from: c:\documents and settings\UserXP\My Documents\البرامج 16\برنامج يعطيك تقرير عن جهازك\اداة فحص الجهاز\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated)
FW: Kaspersky Internet Security *disabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
F:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-04-02 to 2009-05-02 )))))))))))))))))))))))))))))))
.
2009-05-02 20:04 . 2009-05-02 20:04 -------- d-----w c:\windows\system32\NtmsData
2009-05-02 19:39 . 2009-05-02 19:39 -------- d-----w c:\program files\Trend Micro
2009-05-01 20:35 . 2009-05-01 20:35 362240 ----a-w c:\windows\system32\TuneUpDefragService.exe
2009-05-01 20:34 . 2009-05-01 20:34 -------- d-----w c:\documents and settings\UserXP\Application Data\TuneUp Software
2009-05-01 20:00 . 2009-05-02 20:01 -------- d-----w c:\windows\system32\CatRoot2
2009-05-01 13:01 . 2009-05-01 13:01 -------- d--h--w c:\windows\system32\GroupPolicy
2009-05-01 12:15 . 2009-05-01 12:15 96559 ----a-w c:\windows\system32\drivers\klin.dat
2009-05-01 12:15 . 2009-05-01 12:15 87855 ----a-w c:\windows\system32\drivers\klick.dat
2009-05-01 12:14 . 2009-05-01 12:14 -------- d-----w c:\program files\Kaspersky Lab
2009-05-01 11:55 . 2009-05-01 11:55 -------- d-----w c:\documents and settings\UserXP\Application Data\Lavasoft
2009-05-01 11:36 . 2009-05-01 12:53 32 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-01 11:36 . 2009-05-01 12:53 32 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-01 11:36 . 2009-05-01 11:36 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-30 18:29 . 2009-04-30 18:29 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-04-29 09:50 . 2009-04-29 09:50 -------- d--h--w c:\windows\PIF
2009-04-29 09:27 . 2009-04-29 09:50 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-28 11:27 . 2009-04-28 11:27 74 ---ha-w c:\windows\uce.dat
2009-04-28 11:26 . 2009-04-28 11:26 -------- d-----w c:\program files\Ulead Systems
2009-04-28 11:26 . 1999-10-15 10:50 1056768 ------w c:\windows\system32\ROBOEX32.DLL
2009-04-27 23:09 . 2007-04-18 20:07 53248 ----a-w c:\windows\system32\mgxasio2.dll
2009-04-27 07:38 . 2009-04-27 07:38 75 --sh--r c:\windows\ICMET20.BIN
2009-04-27 07:37 . 2009-04-27 07:37 -------- d-----w c:\program files\Reallusion
2009-04-27 07:28 . 2009-04-29 16:19 -------- d-----w c:\documents and settings\UserXP\Application Data\MAGIX
2009-04-27 07:26 . 2009-04-29 16:19 -------- d-----w c:\documents and settings\All Users\Application Data\MAGIX
2009-04-27 07:25 . 2009-04-27 23:08 -------- d-----w c:\program files\MAGIX
2009-04-27 07:25 . 2007-04-27 07:43 120200 ----a-w c:\windows\system32\DLLDEV32i.dll
2009-04-27 07:25 . 2009-04-29 16:18 -------- d-----w c:\windows\system32\MAGIX
2009-04-27 07:25 . 2007-12-04 12:20 700416 ----a-w c:\windows\system32\mgxoschk.dll
2009-04-26 19:47 . 2001-09-18 12:04 5632 ----a-w c:\windows\system32\ptpusb.dll
2009-04-26 19:47 . 2008-04-14 19:29 159232 ----a-w c:\windows\system32\ptpusd.dll
2009-04-26 19:47 . 2008-04-13 22:15 15104 ----a-w c:\windows\system32\drivers\usbscan.sys
2009-04-26 10:32 . 2009-04-26 10:32 -------- d-----w c:\documents and settings\UserXP\Local Settings\Application Data\Help
2009-04-26 07:54 . 2008-04-13 22:09 5504 ----a-w c:\windows\system32\drivers\MSTEE.sys
2009-04-26 07:54 . 2008-04-13 22:16 10880 ----a-w c:\windows\system32\drivers\NdisIP.sys
2009-04-26 07:54 . 2008-04-13 22:16 15232 ----a-w c:\windows\system32\drivers\StreamIP.sys
2009-04-26 07:54 . 2008-04-13 22:16 11136 ----a-w c:\windows\system32\drivers\SLIP.sys
2009-04-26 07:54 . 2008-04-13 22:16 19200 ----a-w c:\windows\system32\drivers\WSTCODEC.SYS
2009-04-26 07:54 . 2008-04-13 22:16 85248 ----a-w c:\windows\system32\drivers\NABTSFEC.sys
2009-04-26 07:54 . 2008-04-13 22:16 17024 ----a-w c:\windows\system32\drivers\CCDECODE.sys
2009-04-26 07:54 . 2006-11-03 14:13 226816 ----a-w c:\windows\system32\drivers\wisgostrm.sys
2009-04-26 07:54 . 2006-01-24 13:17 30800 ----a-w c:\windows\go7007fw.bin
2009-04-26 07:54 . 2006-01-24 13:17 208 ----a-w c:\windows\go7007fw_pf.bin
2009-04-26 07:54 . 2006-01-24 13:17 143540 ----a-w c:\windows\go7007sb.bin
2009-04-26 07:54 . 2008-04-14 19:29 53760 ----a-w c:\windows\system32\vfwwdm32.dll
2009-04-26 07:51 . 2009-04-26 07:51 -------- d-----w c:\windows\system32\LogFiles
2009-04-26 07:10 . 2003-09-11 12:36 21060 ------w c:\windows\system32\drivers\iviaspi.sys
2009-04-26 07:09 . 2009-04-26 07:09 -------- d-----w c:\program files\Common Files\InterVideo
2009-04-26 07:09 . 2009-04-26 07:09 -------- d-----w c:\program files\InterVideo
2009-04-25 11:52 . 2009-04-25 11:52 -------- d-----w c:\documents and settings\UserXP\Application Data\Nero
2009-04-25 11:52 . 2009-04-25 11:52 -------- d-----w c:\documents and settings\UserXP\Local Settings\Application Data\Xenocode
2009-04-24 22:37 . 2005-09-23 21:18 171520 ----a-w c:\windows\system32\drivers\MarvinBus.sys
2009-04-24 22:37 . 2009-04-24 22:37 -------- d-----w c:\program files\Common Files\Pinnacle
2009-04-24 22:37 . 2009-04-24 22:37 -------- d-----w c:\documents and settings\UserXP\Local Settings\Application Data\Downloaded Installations
2009-04-24 22:36 . 2009-04-24 22:36 -------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle Studio Ultimate
2009-04-24 22:33 . 2009-04-24 22:33 -------- d-----w c:\program files\Common Files\Yahoo!
2009-04-24 22:33 . 2009-04-24 22:33 -------- d-----w c:\program files\Pinnacle
2009-04-24 22:33 . 2009-04-24 22:33 -------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle Studio Plus
2009-04-24 22:33 . 2009-04-24 22:33 -------- d-----w c:\documents and settings\All Users\Application Data\Studio 12
2009-04-24 22:29 . 2009-04-24 22:33 -------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle
2009-04-24 15:02 . 2002-03-17 00:00 7420 ----a-w c:\windows\UA000104.DLL
2009-04-24 14:32 . 2009-04-24 22:24 -------- d-----w c:\documents and settings\UserXP\Application Data\Desktopicon
2009-04-24 14:32 . 2009-04-24 14:32 -------- d-----w c:\program files\FormatFactory
2009-04-24 14:25 . 2009-04-28 11:27 -------- d-----w c:\documents and settings\UserXP\Application Data\Ulead Systems
2009-04-24 14:23 . 2009-04-24 14:23 -------- d-----w c:\documents and settings\All Users\Application Data\InterVideo
2009-04-24 14:23 . 2008-04-01 19:40 209040 ----a-w c:\windows\system32\IVIresizeW7.dll
2009-04-24 14:23 . 2008-04-01 19:40 196752 ----a-w c:\windows\system32\IVIresizeP6.dll
2009-04-24 14:23 . 2008-04-01 19:40 192656 ----a-w c:\windows\system32\IVIresizePX.dll
2009-04-24 14:23 . 2008-04-01 19:40 204944 ----a-w c:\windows\system32\IVIresizeA6.dll
2009-04-24 14:23 . 2008-04-01 19:40 196752 ----a-w c:\windows\system32\IVIresizeM6.dll
2009-04-24 14:23 . 2008-04-01 19:40 24720 ----a-w c:\windows\system32\IVIresize.dll
2009-04-24 14:22 . 2009-04-24 14:22 -------- d-----w c:\program files\Windows Media Components
2009-04-24 14:20 . 2009-04-28 11:27 -------- d-----w c:\documents and settings\All Users\Application Data\Ulead Systems
2009-04-24 14:20 . 2009-04-24 14:22 -------- d-----w c:\program files\Common Files\Ulead Systems
2009-04-24 14:18 . 2009-04-24 14:20 -------- d-----w c:\program files\Corel
2009-04-24 14:18 . 2009-04-24 14:18 -------- d-----w c:\documents and settings\UserXP\Application Data\InstallShield
2009-04-24 13:24 . 2009-04-30 18:22 -------- d-----w c:\documents and settings\UserXP\Local Settings\Application Data\Google
2009-04-24 13:21 . 2009-04-24 13:21 -------- d-----w c:\program files\Common Files\xing shared
2009-04-24 13:21 . 2009-04-29 22:23 -------- d-----w c:\program files\Google
2009-04-24 13:21 . 2009-04-24 13:21 -------- d-----w c:\program files\Common Files\Real
2009-04-24 13:21 . 2009-04-24 13:21 -------- d-----w c:\program files\Real
2009-04-24 07:06 . 2009-05-02 18:49 -------- d-----w c:\documents and settings\UserXP\Local Settings\Application Data\Opera
2009-04-24 07:06 . 2009-04-24 07:06 -------- d-----w c:\documents and settings\UserXP\Local Settings\Application Data\Thinstall
2009-04-24 01:00 . 2009-04-24 01:00 -------- d-----w c:\program files\MSXML 4.0
2009-04-23 22:42 . 2009-04-23 22:42 -------- d-s---w c:\documents and settings\UserXP\UserData
2009-04-23 21:12 . 2009-04-23 21:12 -------- d-----w c:\documents and settings\UserXP\Application Data\Sonic
2009-04-23 20:55 . 2008-06-14 17:31 271616 ------w c:\windows\system32\drivers\bthport.sys
2009-04-23 20:53 . 2009-04-29 12:15 -------- d-----w c:\documents and settings\UserXP\Local Settings\Application Data\Adobe
2009-04-23 20:53 . 2009-04-24 15:47 -------- d-----w c:\program files\Common Files\Adobe
2009-04-23 20:25 . 2009-04-23 20:25 -------- d-----w c:\program files\ALLCapture 3.0
2009-04-23 20:24 . 2009-04-25 12:22 -------- d-----w c:\documents and settings\UserXP\Application Data\ALLCapture
2009-04-23 20:24 . 2009-04-23 20:27 -------- d-----w c:\program files\ALLCapture 3.0 Trial
2009-04-23 20:21 . 2008-07-09 07:34 26488 ----a-w c:\windows\system32\spupdsvc.exe
2009-04-23 20:21 . 2009-04-24 05:53 -------- d--h--w c:\windows\$hf_mig$
2009-04-23 20:19 . 2001-08-17 13:59 3072 ----a-w c:\windows\system32\drivers\audstub.sys
2009-04-23 20:18 . 2008-04-14 21:07 57472 ----a-w c:\windows\system32\drivers\redbook.sys
2009-04-23 20:18 . 2001-08-17 13:46 6400 ----a-w c:\windows\system32\drivers\enum1394.sys
2009-04-23 20:17 . 2008-04-14 21:29 73728 ----a-w c:\windows\system32\usbui.dll
2009-04-23 20:17 . 2008-04-14 00:06 10240 ----a-w c:\windows\system32\drivers\compbatt.sys
2009-04-23 20:17 . 2008-04-14 21:05 16384 ----a-w c:\windows\system32\drivers\battc.sys
2009-04-23 20:17 . 2008-04-14 00:06 13952 ----a-w c:\windows\system32\drivers\CmBatt.sys
2009-04-23 20:15 . 2009-04-23 19:10 -------- d-----w c:\documents and settings\All Users
2009-04-23 20:15 . 2009-04-23 18:31 -------- d--h--w c:\documents and settings\Default User
2009-04-23 20:15 . 2009-04-23 18:40 -------- d-----w C:\Documents and Settings
2009-04-23 20:09 . 2009-04-23 20:09 114688 ----a-w c:\windows\system32\TODDSrv.exe
2009-04-23 20:09 . 2009-04-23 20:09 15360 ----a-w c:\windows\system32\drivers\tdcmdpst.sys
2009-04-23 20:07 . 2005-06-14 08:00 108544 ------w c:\windows\system32\pxcpyi64.exe
2009-04-23 20:07 . 2005-04-25 09:03 109568 ------w c:\windows\system32\pxinsi64.exe
2009-04-23 20:06 . 2005-06-02 01:33 102384 ----a-w c:\windows\system32\drivers\meiudf.sys
2009-04-23 20:06 . 2004-08-27 22:33 110592 ----a-w c:\windows\system32\DVDRAMSV.exe
2009-04-23 20:06 . 2004-08-27 22:37 155648 ----a-w c:\windows\system32\RAMASST.exe
2009-04-23 20:06 . 2005-04-22 02:36 135168 ----a-w c:\windows\system32\DVDMenu.dll
2009-04-23 20:06 . 2009-04-23 20:06 -------- d-----w c:\program files\DVD-RAM
2009-04-23 20:05 . 2005-09-12 01:30 89264 ----a-w c:\windows\system32\drivers\DRVMCDB.SYS
2009-04-23 20:05 . 2005-08-12 03:20 40544 ----a-w c:\windows\system32\drivers\DRVNDDM.SYS
2009-04-23 20:05 . 2005-08-25 10:16 5628 ----a-w c:\windows\system32\drivers\DLACDBHM.SYS
2009-04-23 20:05 . 2005-08-25 10:16 22684 ----a-w c:\windows\system32\drivers\DLARTL_N.SYS
2009-04-23 20:05 . 2005-10-06 03:20 61500 ----a-w c:\windows\system32\DLAAPI_W.DLL
2009-04-23 20:05 . 2005-10-06 03:20 94263 ----a-w c:\windows\DLA.EXE
2009-04-23 20:05 . 2009-05-02 20:04 -------- d-----w c:\windows\system32\DLA
2009-04-23 20:05 . 2009-04-23 20:07 -------- d-----w c:\program files\Sonic
2009-04-23 20:05 . 2003-10-09 15:55 20966970 ----a-w c:\windows\cfdemo.exe
2009-04-23 20:05 . 2004-12-08 14:04 45056 ----a-w c:\windows\cfdemo.scr
2009-04-23 20:04 . 2003-01-29 12:35 12032 ----a-w c:\windows\system32\drivers\Netdevio.sys
2009-04-23 20:01 . 2005-05-03 16:43 143360 ----a-w c:\windows\Alcmtr.exe
2009-04-23 19:51 . 2009-04-29 12:15 -------- d-----w c:\documents and settings\UserXP\Application Data\Thinstall
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-02 20:04 . 2009-04-23 18:40 6 ---ha-w c:\windows\Tasks\SA.DAT
2009-05-02 18:10 . 2009-05-02 18:10 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-02 18:05 . 2009-04-23 16:20 58920 ----a-w c:\windows\system32\perfc001.dat
2009-05-02 18:05 . 2009-04-23 16:20 328690 ----a-w c:\windows\system32\perfh001.dat
2009-05-01 20:00 . 2009-04-23 16:10 67 --sha-w c:\windows\Fonts\desktop.ini
2009-05-01 12:53 . 2009-05-01 11:36 32 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-01 12:53 . 2009-05-01 11:36 32 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-27 10:26 . 2009-04-23 18:41 91288 ----a-w c:\documents and settings\UserXP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-23 19:13 . 2009-04-23 19:13 -------- d-----w c:\program files\Apoint2K
2009-04-23 18:31 . 2009-04-23 18:31 -------- d-----w c:\program files\microsoft frontpage
2009-04-23 18:28 . 2009-04-23 18:28 22144 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-06 14:20 . 2009-04-23 16:20 283136 ----a-w c:\windows\system32\pdh.dll
2009-02-20 08:09 . 2009-04-23 16:25 664576 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:09 . 2009-04-23 16:13 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 14:04 . 2009-04-23 16:25 1846656 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:22 . 2008-04-14 21:12 2025472 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:22 . 2009-04-23 16:19 2146816 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:21 . 2009-04-23 16:21 110592 ----a-w c:\windows\system32\services.exe
2009-02-09 10:51 . 2009-04-23 16:14 723456 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:51 . 2009-04-23 16:21 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:51 . 2009-04-23 16:08 681472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:51 . 2009-04-23 16:19 693760 ----a-w c:\windows\system32\ntdll.dll
2009-02-06 10:39 . 2009-04-23 16:21 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:57 . 2009-04-23 16:21 56832 ----a-w c:\windows\system32\secur32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
c:\documents and settings\All Users\çںê، ں*§ڑ\ںé*©ںê¤\*§ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-4-24 183296]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-4-7 1773568]
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2009-4-26 200704]
PC Health.lnk - c:\program files\Toshiba\TOSHIBA Management Console\TOSHealthLocalS.vbs [2009-4-23 3531]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2009-4-23 155648]
«©م، ¢¬نïé Adobe Reader.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 117872]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 1605724]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [2004-12-27 16384]
S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [2004-11-13 6144]
S1 TMEI3E;TMEI3E;c:\windows\system32\Drivers\TMEI3E.SYS [2004-06-16 5888]
S2 Tmesrv;Tmesrv3;c:\program files\TOSHIBA\TME3\Tmesrv31.exe [2005-12-14 126976]
S3 abp470n5;abp470n5; [x]
S3 IFXTPM;IFXTPM;c:\windows\system32\DRIVERS\IFXTPM.SYS [2005-06-10 35968]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MESSENGER
*NewlyCreated* - NETLOGON
*NewlyCreated* - NTMSSVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\M.MIRA.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{855ee75a-3378-11de-8fd4-00037aee8bb2}]
\Shell\AutoRun\command - G:\semo2x.exe
\Shell\explore\Command - G:\semo2x.exe
\Shell\open\Command - G:\semo2x.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9eccf1b0-3028-11de-a3d6-806d6172696f}]
\Shell\AutoRun\command - G:\setup.exe
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-02 23:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,6f,b4,1e,d2,2f,
34,9d,0f,e2,63,26,f1,3f,c8,ff,68,d7,ff,f5,d4,33,8c,d0,e7,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,5a,91,c2,d0,8c,
f4,b8,6d,6a,9c,d6,61,af,45,84,18,df,eb,ed,98,b0,89,0e,2a,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,85,bc,3e,65,89,
c4,ef,a9,ff,7c,85,e0,43,d4,0e,fe,41,e4,66,0d,be,27,6a,b8,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,c9,ba,0a,fb,60,
99,d3,d5,86,8c,21,01,be,91,eb,e7,c0,5f,a6,06,e5,dc,6a,6d,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,33,ef,c7,72,cc,
45,1f,1f,f5,1d,4d,73,a8,13,5c,05,a3,32,16,15,68,e5,52,58,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,ef,7c,20,ad,55,
6f,45,ae,df,20,58,62,78,6b,cf,c8,db,be,4f,65,a2,80,66,8c,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,38,5e,45,8f,b8,
c2,e6,3a,fb,a7,78,e6,12,2f,9a,ea,ac,fc,88,6d,84,4a,74,69,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,63,48,04,49,d6,
01,8d,78,01,3a,48,fc,e8,04,4a,f1,4b,86,25,5b,2b,51,2e,1a,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,ac,c1,33,e5,26,
50,12,cd,f6,0f,4e,58,98,5b,89,c9,cf,65,73,7e,81,49,e2,12,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,15,bf,d1,38,d1,
79,80,09,3d,ce,ea,26,2d,45,aa,78,00,1c,21,62,24,07,7d,76,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,15,8a,6e,4c,a4,
89,eb,32,2a,b7,cc,b5,b9,7f,41,e7,5b,19,1a,69,4c,2b,70,e6,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,5d,3a,16,88,36,
97,a8,c5,6c,43,2d,1e,aa,22,2f,9c,ec,06,ac,d4,1f,e9,af,f1,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3812)
c:\program files\TOSHIBA\TME3\TMEEJMD.DLL
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\acs.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\windows\system32\ThpSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\igfxtray.exe
c:\windows\system32\hkcmd.exe
c:\windows\system32\igfxpers.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\SkyTel.exe
c:\windows\RTHDCPL.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\windows\system32\DLA\DLACTRLW.EXE
c:\program files\Apoint2K\Apoint.exe
c:\windows\system32\
00THotkey.exe
c:\program files\Toshiba\DualPointUtility\TEDTray.exe
c:\windows\system32\ThpSrv.exe
c:\windows\system32\TFNF5.exe
c:\windows\system32\TPSBattM.exe
c:\program files\Toshiba\TME3\TMERzCtl.exe
c:\program files\ltmoh\ltmoh.exe
c:\windows\agrsmmsg.exe
c:\toshiba\IVP\ISM\pinger.exe
c:\program files\Apoint2K\ApntEx.exe
c:\program files\Toshiba\Wireless Hotkey\TosHKCW.exe
c:\program files\Toshiba\TME3\TMEEJME.exe
c:\windows\system32\igfxext.exe
c:\program files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe
c:\program files\Common Files\Real\Update_OB\realsched.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
.
**************************************************************************
.
Completion time: 2009-05-02 23:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-02 20:07
Pre-Run: 62,277,062,656 bytes free
Post-Run: 62,439,518,208 bytes free
371 --- E O F --- 2009-04-24 06:44