ComboFix 09-06-06.03 - vista 06/07/2009 15:23.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1256.966.1033.18.1014.385 [GMT 3:00]
Running from: c:\users\vista\Desktop\ملفاتي\برامج\ComboFix.exe
AV: BitDefender 8.0 Professional Plus *On-access scanning disabled* (Outdated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: BitDefender 8.0 Professional Plus *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Kaspersky Internet Security *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\antispy2
c:\program files\antispy2\anti_spy.exe
c:\program files\antispy2\s.txt
c:\program files\antispy2\Uninstall\IRIMG1.JPG
c:\program files\antispy2\Uninstall\IRIMG2.JPG
c:\program files\antispy2\Uninstall\IRIMG3.JPG
c:\program files\antispy2\Uninstall\uninstall.dat
c:\program files\antispy2\Uninstall\uninstall.xml
c:\users\vista\AppData\Local\Temp\ppcrlui_3788_2
c:\windows\system32\drivers\Msft_Kernel_Apfiltr_01001.Wdf
c:\windows\system32\drivers\Msft_Kernel_TpChoice_01005.Wdf
c:\windows\system32\drivers\TOSHIBA_Satellite A200_04989-AR_PSAE0E-02G00.MRK
.
((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
.
2009-06-07 12:21 . 2009-06-07 12:27 -------- d-s---w- \ComboFix
2009-06-07 12:21 . 2009-06-07 12:21 -------- d-----w- \Qoobox
2009-06-07 07:13 . 2009-06-07 07:13 198064 ----a-w- c:\users\vista\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
2009-06-07 07:12 . 2009-06-07 12:27 -------- d-----w- c:\users\vista\AppData\Roaming\DMCache
2009-06-07 07:12 . 2009-06-07 10:58 -------- d-----w- c:\users\vista\AppData\Roaming\IDM
2009-06-07 07:12 . 2009-06-07 11:36 -------- d-----w- c:\program files\Internet Download Manager
2009-06-07 06:47 . 2008-06-26 00:33 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-06-07 06:47 . 2008-06-26 00:33 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2009-06-07 06:45 . 2008-06-26 00:34 5499904 ----a-w- c:\windows\system32\NlsLexicons0022.dll
2009-06-06 10:10 . 2009-06-06 10:10 61440 ----a-w- c:\windows\system32\ntprint.exe
2009-06-06 10:10 . 2009-06-06 10:10 220160 ----a-w- c:\windows\system32\ntprint.dll
2009-06-06 10:10 . 2009-06-06 10:10 10240 ----a-w- c:\windows\system32\dhcpcmonitor.dll
2009-06-06 10:10 . 2009-06-06 10:10 120320 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2009-06-06 10:10 . 2009-06-06 10:10 1984512 ----a-w- c:\windows\system32\authui.dll
2009-06-06 10:09 . 2009-06-06 10:09 88576 ----a-w- c:\windows\system32\avifil32.dll
2009-06-06 10:09 . 2009-06-06 10:09 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-06-06 10:09 . 2009-06-06 10:09 65024 ----a-w- c:\windows\system32\avicap32.dll
2009-06-06 10:09 . 2009-06-06 10:09 31232 ----a-w- c:\windows\system32\msvidc32.dll
2009-06-06 10:09 . 2009-06-06 10:09 12800 ----a-w- c:\windows\system32\msrle32.dll
2009-06-06 10:09 . 2009-06-06 10:09 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-06-06 10:09 . 2009-06-06 10:09 69632 ----a-w- c:\windows\system32\sendmail.dll
2009-06-06 10:09 . 2009-06-06 10:09 8138240 ----a-w- c:\windows\system32\ssBranded.scr
2009-06-06 07:32 . 2009-06-06 07:32 206088 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-06-06 07:32 . 2009-06-06 07:32 33808 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
2009-06-06 07:32 . 2009-06-06 07:32 239120 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\Vista\klif.sys
2009-06-06 04:40 . 2009-06-06 07:33 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-06-06 04:40 . 2009-06-06 07:33 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-06-06 04:39 . 2009-06-07 12:02 -------- d-----w- c:\programdata\Kaspersky Lab
2009-06-06 04:39 . 2009-06-07 12:01 270368 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-06 04:39 . 2009-06-07 12:01 1921056 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-06 04:39 . 2009-06-06 04:39 -------- d-----w- c:\program files\Kaspersky Lab
2009-06-06 04:36 . 2009-06-06 04:36 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2009-06-06 00:05 . 2009-06-06 00:05 70144 ----a-w- c:\windows\system32\drivers\pacer.sys
2009-06-06 00:05 . 2009-06-06 00:05 694784 ----a-w- c:\windows\system32\localspl.dll
2009-06-06 00:05 . 2009-06-06 00:05 33280 ----a-w- c:\windows\system32\traffic.dll
2009-06-06 00:05 . 2009-06-06 00:05 15360 ----a-w- c:\windows\system32\pacerprf.dll
2009-06-06 00:05 . 2009-06-06 00:05 13824 ----a-w- c:\windows\system32\wshqos.dll
2009-06-06 00:05 . 2009-06-06 00:05 619008 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-06-06 00:05 . 2009-06-06 00:05 36864 ----a-w- c:\windows\system32\cdd.dll
2009-06-06 00:05 . 2009-06-06 00:05 134656 ----a-w- c:\windows\system32\dps.dll
2009-06-06 00:04 . 2009-06-06 00:04 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-06-06 00:04 . 2009-06-06 00:04 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-06-06 00:04 . 2009-06-06 00:04 1687040 ----a-w- c:\windows\system32\gameux.dll
2009-06-06 00:04 . 2009-06-06 00:04 356864 ----a-w- c:\windows\system32\MediaMetadataHandler.dll
2009-06-06 00:01 . 2009-06-06 00:01 223232 ----a-w- c:\windows\system32\SLC.dll
2009-06-06 00:01 . 2009-06-06 00:01 33280 ----a-w- c:\windows\system32\slwmi.dll
2009-06-06 00:01 . 2009-06-06 00:01 268288 ----a-w- c:\windows\system32\mcbuilder.exe
2009-06-06 00:01 . 2009-06-06 00:01 566784 ----a-w- c:\windows\system32\SLCommDlg.dll
2009-06-06 00:01 . 2009-06-06 00:01 351232 ----a-w- c:\windows\system32\SLUI.exe
2009-06-06 00:01 . 2009-06-06 00:01 186368 ----a-w- c:\windows\system32\SLLUA.exe
2009-06-06 00:01 . 2009-06-06 00:01 57856 ----a-w- c:\windows\system32\SLUINotify.dll
2009-06-06 00:00 . 2009-06-06 00:01 2605568 ----a-w- c:\windows\system32\SLsvc.exe
2009-06-06 00:00 . 2009-06-06 00:00 39936 ----a-w- c:\windows\system32\slcinst.dll
2009-06-05 09:36 . 2009-06-05 09:36 -------- d-----w- c:\windows\مضاد التجسس
2009-06-05 09:23 . 2009-06-05 09:23 -------- d-----w- c:\program files\MSN Messenger
2009-06-05 09:23 . 2009-06-05 09:23 -------- d-----w- c:\windows\PCHEALTH
2009-06-05 07:20 . 2009-06-05 07:20 268800 ----a-w- c:\windows\system32\es.dll
2009-06-05 07:18 . 2009-06-05 07:18 7680 ----a-w- c:\windows\system32\lsass.exe
2009-06-05 07:18 . 2009-06-05 07:18 72704 ----a-w- c:\windows\system32\secur32.dll
2009-06-05 07:18 . 2009-06-05 07:18 1233408 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-05 07:18 . 2009-06-05 07:18 25600 ----a-w- c:\windows\system32\amxread.dll
2009-06-05 07:18 . 2009-06-05 07:18 14848 ----a-w- c:\windows\system32\apilogen.dll
2009-06-05 07:18 . 2009-06-05 07:18 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-06-05 07:18 . 2009-06-05 07:18 712192 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-06-05 07:17 . 2009-06-05 07:17 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-06-05 07:17 . 2009-06-05 07:17 -------- d-----w- c:\program files\MSXML 4.0
2009-06-05 04:56 . 2009-06-05 04:56 -------- d-----w- C:\DepositFiles
2009-06-05 04:56 . 2009-06-05 04:56 -------- d-----w- \DepositFiles
2009-06-05 02:03 . 2009-06-05 02:03 98816 ----a-w- c:\windows\system32\mfps.dll
2009-06-05 02:03 . 2009-06-05 02:03 52736 ----a-w- c:\windows\system32\rrinstaller.exe
2009-06-05 02:03 . 2009-06-05 02:03 2855424 ----a-w- c:\windows\system32\mf.dll
2009-06-05 02:03 . 2009-06-05 02:03 2048 ----a-w- c:\windows\system32\mferror.dll
2009-06-05 02:03 . 2009-06-05 02:03 24576 ----a-w- c:\windows\system32\mfpmp.exe
2009-06-05 02:03 . 2009-06-05 02:03 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2009-06-05 02:03 . 2009-06-05 02:03 94720 ----a-w- c:\windows\system32\logagent.exe
2009-06-04 12:43 . 2009-06-04 12:43 61440 ----a-w- c:\windows\system32\winipsec.dll
2009-06-04 12:43 . 2009-06-04 12:43 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2009-06-04 12:43 . 2009-06-04 12:43 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2009-06-04 12:43 . 2009-06-04 12:43 272896 ----a-w- c:\windows\system32\polstore.dll
2009-06-04 12:43 . 2009-06-04 12:43 87040 ----a-w- c:\windows\system32\msoert2.dll
2009-06-04 12:43 . 2009-06-04 12:43 39424 ----a-w- c:\windows\system32\ACCTRES.dll
2009-06-04 12:43 . 2009-06-04 12:43 205824 ----a-w- c:\windows\system32\msoeacct.dll
2009-06-04 12:42 . 2009-06-04 12:42 194560 ----a-w- c:\windows\system32\WebClnt.dll
2009-06-04 12:42 . 2009-06-04 12:42 110080 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2009-06-04 12:42 . 2009-06-04 12:42 376832 ----a-w- c:\windows\system32\winhttp.dll
2009-06-04 12:41 . 2009-06-04 12:41 297472 ----a-w- c:\windows\system32\gdi32.dll
2009-06-04 12:41 . 2009-06-04 12:41 500736 ----a-w- c:\windows\system32\msdtcprx.dll
2009-06-04 12:41 . 2009-06-04 12:41 30208 ----a-w- c:\windows\system32\xolehlp.dll
2009-06-04 12:40 . 2009-06-04 12:40 2048 ----a-w- c:\windows\system32\msxml3r.dll
2009-06-04 12:40 . 2009-06-04 12:40 1194496 ----a-w- c:\windows\system32\msxml3.dll
2009-06-04 12:40 . 2009-06-04 12:40 2923520 ----a-w- c:\windows\explorer.exe
2009-06-04 12:39 . 2009-06-04 12:39 14848 ----a-w- c:\windows\system32\wshrm.dll
2009-06-04 12:39 . 2009-06-04 12:39 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2009-06-04 12:38 . 2009-06-04 12:38 11776 ----a-w- c:\windows\system32\sbunattend.exe
2009-06-04 12:38 . 2009-06-04 12:38 290304 ----a-w- c:\windows\system32\drivers\srv.sys
2009-06-04 12:37 . 2009-06-04 12:37 1645568 ----a-w- c:\windows\system32\connect.dll
2009-06-04 12:37 . 2009-06-04 12:37 1327104 ----a-w- c:\windows\system32\quartz.dll
2009-06-04 01:50 . 2009-06-04 01:50 -------- d-----w- c:\program files\Lavasoft
2009-06-04 01:31 . 2009-06-04 02:42 -------- d-----w- c:\program files\Common Files\Softwin
2009-06-04 01:31 . 2009-06-04 01:31 -------- d-----w- c:\program files\Softwin
2009-06-03 15:58 . 2009-06-03 15:58 95232 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-06-03 15:58 . 2009-06-03 15:58 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-06-03 15:58 . 2009-06-03 15:58 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-06-03 15:57 . 2009-06-03 15:57 41984 ----a-w- c:\windows\system32\drivers\monitor.sys
2009-06-03 15:57 . 2009-06-03 15:57 1060920 ----a-w- c:\windows\system32\drivers\ntfs.sys
2009-06-03 15:57 . 2009-06-03 15:57 211456 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-06-03 15:56 . 2009-06-03 15:56 374456 ----a-w- c:\windows\system32\mcupdate_GenuineIntel.dll
2009-06-03 15:56 . 2009-06-03 15:56 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2009-06-03 15:55 . 2009-06-03 15:55 414208 ----a-w- c:\windows\system32\msscp.dll
2009-06-03 15:55 . 2009-06-03 15:55 63488 ----a-w- c:\windows\system32\drivers\mpsdrv.sys
2009-06-03 15:55 . 2009-06-03 15:55 396800 ----a-w- c:\windows\system32\MPSSVC.dll
2009-06-03 15:55 . 2009-06-03 15:55 392192 ----a-w- c:\windows\system32\FirewallAPI.dll
2009-06-03 15:55 . 2009-06-03 15:55 86016 ----a-w- c:\windows\system32\icfupgd.dll
2009-06-03 15:55 . 2009-06-03 15:55 61952 ----a-w- c:\windows\system32\cmifw.dll
2009-06-03 15:55 . 2009-06-03 15:55 23040 ----a-w- c:\windows\system32\drivers\tunnel.sys
2009-06-03 15:55 . 2009-06-03 15:55 178688 ----a-w- c:\windows\system32\iphlpsvc.dll
2009-06-03 15:55 . 2009-06-03 15:55 16896 ----a-w- c:\windows\system32\wfapigp.dll
2009-06-03 15:55 . 2009-06-03 15:55 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2009-06-03 15:54 . 2009-06-03 15:54 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2009-06-03 15:54 . 2009-06-03 15:54 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-06-03 15:54 . 2009-06-03 15:54 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-06-03 15:54 . 2009-06-03 15:54 104448 ----a-w- c:\windows\system32\DWWIN.EXE
2009-06-03 15:52 . 2009-06-03 15:52 97280 ----a-w- c:\windows\system32\iasrecst.dll
2009-06-03 15:52 . 2009-06-03 15:52 53248 ----a-w- c:\windows\system32\iasads.dll
2009-06-03 15:52 . 2009-06-03 15:52 37888 ----a-w- c:\windows\system32\iasdatastore.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-07 12:01 . 2009-06-03 09:06 1063378944 --sha-w- \hiberfil.sys
2009-06-07 12:01 . 2009-06-03 09:01 1377304576 --sha-w- \pagefile.sys
2009-06-07 12:01 . 2009-06-06 04:39 2004 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-07 12:01 . 2009-06-06 04:39 16088 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-06 07:33 . 2008-01-29 14:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-06-06 05:03 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-06-06 00:09 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-06-06 00:06 . 2009-06-06 00:06 8192 ----a-w- c:\windows\system32\riched32.dll
2009-06-06 00:06 . 2009-06-06 00:06 20480 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2009-06-06 00:06 . 2009-06-06 00:06 77824 ----a-w- c:\windows\system32\rascfg.dll
2009-06-06 00:06 . 2009-06-06 00:06 61952 ----a-w- c:\windows\system32\drivers\wanarp.sys
2009-06-06 00:06 . 2009-06-06 00:06 52736 ----a-w- c:\windows\system32\rasdiag.dll
2009-06-06 00:06 . 2009-06-06 00:06 48640 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2009-06-06 00:06 . 2009-06-06 00:06 32768 ----a-w- c:\windows\system32\rasmxs.dll
2009-06-06 00:06 . 2009-06-06 00:06 22016 ----a-w- c:\windows\system32\rasser.dll
2009-06-06 00:06 . 2009-06-06 00:06 384000 ----a-w- c:\windows\system32\netcfgx.dll
2009-06-06 00:06 . 2009-06-06 00:06 286208 ----a-w- c:\windows\system32\ipnathlp.dll
2009-06-06 00:06 . 2009-06-06 00:06 13824 ----a-w- c:\windows\system32\icsunattend.exe
2009-06-05 02:06 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-06-04 12:45 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-06-04 12:39 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-06-04 01:21 . 2007-03-08 10:52 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-04 01:18 . 2007-03-08 10:53 -------- d-----w- c:\programdata\Symantec
2009-06-03 15:45 . 2009-06-03 15:45 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-03 15:45 . 2009-06-03 15:45 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-06-03 15:45 . 2009-06-03 15:45 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-06-03 15:45 . 2009-06-03 15:45 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-06-03 09:11 . 2007-03-08 10:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-03 09:10 . 2007-03-08 09:28 -------- d-----w- c:\program files\TOSHIBA
2009-06-03 09:09 . 2007-03-08 10:46 -------- d-----w- c:\program files\InterVideo
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-06-04 1232896]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2006-11-13 413696]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-06-07 2815408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-12-19 411768]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-01-29 509496]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-01-17 534648]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2006-11-01 413696]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-11-01 438272]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-03-02 577536]
"Desktop SMS"="c:\program files\IDM\Desktop SMS\DesktopSMS.exe" [2007-01-19 1507328]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-01-13 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-01-13 7766016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-01-13 81920]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-11-28 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-11-28 106496]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-11-28 81920]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2007-02-19 571024]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-03 180269]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-06-06 206088]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-01-18 4349952]
"NDSTray.exe"="NDSTray.exe" [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\adialhk.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{73050385-9800-4D58-9D4B-99CC9DAA1850}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{EF5A89E8-4EB2-4026-90A3-371B4D037594}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{7F604D55-133D-473A-AFED-25821A0BC91D}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{76C90CE1-EE0A-40EA-BD47-B42AFB1899ED}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{FB5A8BE6-8102-45E9-A4F3-A72D73B77688}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{D9BEA7A0-B82C-4BC4-A65C-E5F5B94F8E30}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{4514ECF5-6617-4EFC-BA77-5BFDFCFE8405}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [29/01/08 05:29 م 33808]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [09/07/08 05:28 م 20496]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\System32\drivers\klfltdev.sys [13/03/08 06:02 م 26640]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\System32\drivers\br3gmdm.sys [29/08/07 05:44 م 100096]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = proxy.nesma.net.sa:8080
IE: إضافة إلى حاجب إعلان الشعار - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
IE: {{C08CAF1D-C0A3-40D5-9970-06D067EAC017} -
LSP: c:\windows\system32\idmmbc.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-07 15:27
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i?????W7?=Ld??8?Y?`?Y???Y???Y??
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-06-07 15:29
ComboFix-quarantined-files.txt 2009-06-07 12:29
Pre-Run: 90,506,129,408 bytes free
Post-Run: 90,303,582,208 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=9 Sets=1,2,3,4,5,6,7,8,9
299 --- E O F --- 2009-06-07 07:19