Sorry to take up so much space; here's the ComboFix log:ComboFix 08-08-19.02 - Someone Else 2008-08-20 9:08:16.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.574 [GMT -5:00]
Running from: C:\Documents and Settings\Someone Else\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Someone Else\Application Data\macromedia\Flash Player\#SharedObjects\HWCRC2VS\interclick.com
C:\Documents and Settings\Someone Else\Application Data\macromedia\Flash Player\#SharedObjects\HWCRC2VS\interclick.com\ud.sol
C:\Documents and Settings\Someone Else\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Someone Else\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Someone Else\Cookies\
[email protected][2].txt
C:\Documents and Settings\Someone Else\Cookies\
[email protected][1].txt
C:\Documents and Settings\Someone Else\Cookies\
[email protected][1].txt
C:\Documents and Settings\Someone Else\Cookies\someone_else@advertising[2].txt
C:\Documents and Settings\Someone Else\Cookies\someone_else@fastclick[1].txt
C:\Documents and Settings\Someone Else\Cookies\someone_else@insightexpressai[1].txt
C:\Documents and Settings\Someone Else\Cookies\someone_else@media6degrees[2].txt
C:\Documents and Settings\Someone Else\Cookies\someone_else@photobucket[1].txt
C:\Documents and Settings\Someone Else\Cookies\someone_else@questionmarket[2].txt
C:\Documents and Settings\Someone Else\Cookies\someone_else@realmedia[2].txt
C:\Documents and Settings\Someone Else\Cookies\someone_else@trafficmp[1].txt
C:\Documents and Settings\Someone Else\Cookies\someone_else@turn[2].txt
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\__c00A170C.dat
C:\WINDOWS\system32\~.exe
.
((((((((((((((((((((((((( Files Created from 2008-07-20 to 2008-08-20 )))))))))))))))))))))))))))))))
.
2008-08-19 19:36 . 2008-08-19 19:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-19 15:02 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-14 22:51 . 2008-05-01 09:30 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-20 14:15 555,040 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-20 14:15 17,506,080 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-20 14:14 53,036 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-20 14:14 235,484 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-20 14:00 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-20 13:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-20 13:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-20 04:04 --------- d-----w C:\Program Files\Java
2008-08-19 03:56 6,926 ----a-w C:\Documents and Settings\Someone Else\Application Data\wklnhst.dat
2008-08-18 02:53 --------- d-----w C:\Documents and Settings\Someone Else\Application Data\toshiba
2008-08-18 02:43 --------- d-----w C:\Program Files\MySpace
2008-08-06 18:49 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-07-27 04:48 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-06-24 21:46 --------- d-----w C:\Program Files\Common Files\ArcSoft
2008-06-24 21:42 --------- d-----w C:\Documents and Settings\Someone Else\Application Data\ArcSoft
2008-06-24 21:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\ArcSoft
2008-06-24 21:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-24 21:41 --------- d-----w C:\Program Files\ArcSoft
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 02:32 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 18:27 9117696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2005-04-05 18:25 73728]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2005-08-10 13:23 356352]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-07 22:02 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-07 21:59 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-07 22:03 114688]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2005-04-12 18:18 184320]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 17:28 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 17:26 688218]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 16:03 1077301]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-26 18:13 122880]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 19:37 151552]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 07:33 122941]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 13:27 385024]
"Notebook Maximizer"="C:\Program Files\Notebook Maximizer\maximizer_startup.exe" [2004-05-25 16:35 28672]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-14 10:00 267064]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-28 12:51 218376]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-12 18:17 88358 C:\WINDOWS\agrsmmsg.exe]
"TFncKy"="TFncKy.exe" [BU]
"TPSMain"="TPSMain.exe" [2005-05-31 23:00 282624 C:\WINDOWS\system32\TPSMain.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
"CFSServ.exe"="CFSServ.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 18:27 9117696]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-07-28 15:56:17 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 13:27 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\TOSHIBA\\ConfigFree\\CFXFER.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Documents and Settings\\Someone Else\\Desktop\\Emulators\\Zsnes(old)\\ZSNESW.EXE"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 16:38]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
.
Contents of the 'Scheduled Tasks' folder
2008-05-15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHANS REMOVED - - - -
Notify-__c00A170C - C:\WINDOWS\system32\__c00A170C.dat
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-20 09:15:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2008-08-20 9:20:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-20 14:20:17
Pre-Run: 85,173,936,128 bytes free
Post-Run: 85,619,974,144 bytes free
172 --- E O F --- 2008-08-18 02:16:48