(1) التقرير الاول
ComboFix 08-07-25.6 - ezmo 07/26/2008 14:16:42.1 - NTFSx86
Running from: C:\Documents and Settings\ezmo\My Documents\Downloads\Programs\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\IEToolbar
C:\Program Files\IEToolbar\Sahate Toolbar\ARROW1.CUR
C:\Program Files\IEToolbar\Sahate Toolbar\basis.xml
C:\Program Files\IEToolbar\Sahate Toolbar\clearhist.exe
C:\Program Files\IEToolbar\Sahate Toolbar\DRAGFOLD.CUR
C:\Program Files\IEToolbar\Sahate Toolbar\favicon.ico
C:\Program Files\IEToolbar\Sahate Toolbar\icons.bmp
C:\Program Files\IEToolbar\Sahate Toolbar\icons.bmp_16.bmp
C:\Program Files\IEToolbar\Sahate Toolbar\icons.bmp_24.bmp
C:\Program Files\IEToolbar\Sahate Toolbar\icons.bmp_32.bmp
C:\Program Files\IEToolbar\Sahate Toolbar\ijl15.dll
C:\Program Files\IEToolbar\Sahate Toolbar\info.txt
C:\Program Files\IEToolbar\Sahate Toolbar\logo.bmp
C:\Program Files\IEToolbar\Sahate Toolbar\logo.png
C:\Program Files\IEToolbar\Sahate Toolbar\mini_logo1.bmp
C:\Program Files\IEToolbar\Sahate Toolbar\options.html
C:\Program Files\IEToolbar\Sahate Toolbar\sahaPen21.exe
C:\Program Files\IEToolbar\Sahate Toolbar\sahate.crc
C:\Program Files\IEToolbar\Sahate Toolbar\sahate.inf
C:\Program Files\IEToolbar\Sahate Toolbar\tbhelper.dll
C:\Program Files\IEToolbar\Sahate Toolbar\tbs_include_script_013267.js
C:\Program Files\IEToolbar\Sahate Toolbar\uninstall.exe
C:\Program Files\IEToolbar\Sahate Toolbar\update.exe
C:\Program Files\IEToolbar\Sahate Toolbar\version.txt
C:\Program Files\IEToolbar\Sahate Toolbar\websave_plugin.dll
C:\Program Files\IEToolbar\Sahate Toolbar\your_logo.png
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\drivers\npf.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Legacy_NPF
-------\Service_Iprip
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-06-26 to 2008-07-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-26 11:24 466,976 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-26 11:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-26 11:23 2,676 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-26 11:22 19,036 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-26 11:22 1,895,968 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-26 11:13 --------- d-----w C:\Documents and Settings\ezmo\Application Data\DMCache
2008-07-26 11:06 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-25 21:36 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-25 21:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-07-25 21:32 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-07-25 08:25 --------- d-----w C:\Program Files\Spyware Doctor
2008-07-25 01:07 --------- d-----w C:\Documents and Settings\ezmo\Application Data\IDM
2008-07-24 12:51 96,559 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-07-24 12:51 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-24 04:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-22 00:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-21 18:13 --------- d-----w C:\Program Files\CAM Development
2008-07-21 18:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\CAM Development
2008-07-21 14:53 --------- d-----w C:\Program Files\SeePassword
2008-07-20 13:04 --------- d-----w C:\Program Files\Java
2008-07-12 21:17 --------- d-----w C:\Program Files\Windows Live
2008-07-12 21:16 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-12 21:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-09 14:34 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
2008-07-03 13:30 --------- d-----w C:\Program Files\Common Files\xing shared
2008-07-03 13:29 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-07-03 13:29 --------- d-----w C:\Program Files\Common Files\Real
2008-07-02 11:38 --------- d-----w C:\Documents and Settings\ezmo\Application Data\PC Tools
2008-06-30 14:32 --------- d-----w C:\Program Files\Gabest
2008-06-30 10:08 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-30 10:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-06-29 21:02 --------- d-----w C:\Documents and Settings\ezmo\Application Data\cleaner
2008-06-23 10:45 --------- d-----w C:\Program Files\Ares Galaxy FasterDownload
2008-06-20 17:36 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 14:09 --------- d-----w C:\Program Files\Ares
2008-06-20 10:44 360,960 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:32 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-17 18:13 --------- d-----w C:\Program Files\Sun
2008-06-17 18:08 --------- d-----w C:\Program Files\Common Files\Java
2008-06-14 17:59 271,616 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 18:22 81,288 ----a-w C:\WINDOWS\system32\drivers\iksyssec.sys
2008-06-07 20:55 --------- d-----w C:\Documents and Settings\ezmo\Application Data\Software Informer
2008-06-02 12:19 66,952 ----a-w C:\WINDOWS\system32\drivers\iksysflt.sys
2008-06-02 12:19 42,376 ----a-w C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-06-02 12:19 29,576 ----a-w C:\WINDOWS\system32\drivers\kcom.sys
2008-06-01 13:49 --------- d-----w C:\Program Files\Yahoo!
2008-05-31 20:07 --------- d-----w C:\Program Files\DSL Speed
2008-05-31 20:06 --------- d-----w C:\Program Files\CCleaner
2008-05-07 04:55 1,286,144 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-29 11:27 2,512 ----a-w C:\WINDOWS\system32\tmp.reg
2008-03-14 21:25 81,920 ----a-w C:\Documents and Settings\ezmo\Application Data\ezpinst.exe
2008-03-14 21:25 47,360 ----a-w C:\Documents and Settings\ezmo\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0A94B116-4504-4e26-AB05-E61E474AA38B}"= "C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL" [04/17/2008 09:34 PM 61440]
[HKEY_CLASSES_ROOT\clsid\{0a94b116-4504-4e26-ab05-e61e474aa38b}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"ares"="C:\Program Files\Ares\Ares.exe" [02/20/2008 05:33 PM 963072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [11/28/2005 08:55 AM 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [11/28/2005 08:52 AM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [11/28/2005 08:55 AM 118784]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM 144784]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"MsmqIntCert"="mqrt.dll" [07/06/2007 03:50 PM 177152 C:\WINDOWS\system32\mqrt.dll]
"RTHDCPL"="RTHDCPL.EXE" [11/14/2006 12:21 PM 16270848 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
07/22/2006 11:49 PM 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hard Disk Sentinel
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 10/27/2006 12:47 AM 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
--a------ 05/16/2006 01:04 PM 2879488 C:\WINDOWS\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\IEPro\\MiniDM.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP

eer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [03/25/2008 08:07 PM]
S2 ioperm;ioperm support for Cygwin driver;C:\HTT-HumaxGbox\cygwin\bin\ioperm.sys []
S3 p2pgasvc;تصديق مجموعة شبكة النظير;C:\WINDOWS\system32\svchost.exe [08/04/2004 01:56 AM]
S3 p2pimsvc;إدارة هوية شبكة النظير;C:\WINDOWS\system32\svchost.exe [08/04/2004 01:56 AM]
S3 p2psvc;شبكة النظير;C:\WINDOWS\system32\svchost.exe [08/04/2004 01:56 AM]
S3 PNRPSvc;بروتوكول حل اسم النظير;C:\WINDOWS\system32\svchost.exe [08/04/2004 01:56 AM]
S3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [06/08/2007 09:52 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{1A295E8E-E51B-42CE-81B2-B73614F0FCD2} - (no file)
HKCU-Run-IDMan - C:\Documents and Settings\ezmo\Local Settings\Temp\RarSFX1\IDMan.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-Internet Settings,ProxyServer = 203.178.133.2:3124
R1 -: HKCU-Internet Settings,ProxyOverride = local;<local>
O8 -: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Documents and Settings\ezmo\Local Settings\Temp\RarSFX1\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - C:\Documents and Settings\ezmo\Local Settings\Temp\RarSFX1\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Documents and Settings\ezmo\Local Settings\Temp\RarSFX1\IEGetVL.htm
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-26 14:24:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Completion time: 07/26/2008 14:28:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-26 11:28:01
Pre-Run: 99,445,960,704 bytes free
Post-Run: 99,947,433,984 bytes free
210 --- E O F --- 2008-07-22 00:01:14
===========================================================
التقرير الثاني
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:32:24 م, on 26/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ares\Ares.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Netscape\Navigator 9\navigator.exe
C:\Documents and Settings\ezmo\My Documents\Downloads\Programs\Zyzoom_HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 203.178.133.2:3124
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: IE7Pro BHO - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Documents and Settings\ezmo\Local Settings\Temp\RarSFX1\IDMIECC.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Documents and Settings\ezmo\Local Settings\Temp\RarSFX1\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Documents and Settings\ezmo\Local Settings\Temp\RarSFX1\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Documents and Settings\ezmo\Local Settings\Temp\RarSFX1\IEGetVL.htm
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
--
End of file - 8412 bytes