ابلصق التقرير لكن سؤال : هل لما اسوي تهيئه للدي يعطيني مساحه اكبر ؟؟
المهم التقرير .,.
ComboFix 08-10-17.01 - desktop 10/18/2008 20:47:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.683 [GMT 3:00]
Running from: C:\Documents and Settings\desktop\My Documents\Downloads\Programs\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\FlashGetBHO
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\FlashGetBHO.dll
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\FlashGetBHO1.dll
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\FlvDetector.exe
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\FlvDetector.ini
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\LiveQuery.exe
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\LiveSupport.exe
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\zlib.dll
C:\Documents and Settings\desktop\Application Data\.#
C:\Documents and Settings\desktop\Application Data\.#\MBX@448@3939D0.###
C:\Documents and Settings\desktop\Application Data\.#\MBX@448@3939E0.###
C:\Documents and Settings\desktop\Application Data\.#\MBX@DB8@3A39D0.###
C:\Documents and Settings\desktop\Application Data\.#\MBX@DB8@3A39E0.###
C:\Documents and Settings\desktop\Application Data\BITS
C:\Documents and Settings\desktop\Application Data\BITS\BITS.ini
C:\Documents and Settings\desktop\Application Data\BITS\DHTTable.dat
C:\Documents and Settings\desktop\Application Data\BITS\ProxyList.ini
C:\Documents and Settings\desktop\Application Data\BITS\UPnP.ini
C:\Program Files\FlashGet Network
C:\Program Files\FlashGet Network\Flashget\Bhocfg.ini
C:\Program Files\FlashGet Network\Flashget\dbtrans_verbose.log
C:\Program Files\FlashGet Network\Flashget\fgoption.ini
C:\Program Files\FlashGet Network\Flashget\FlvDetector.ini
C:\Program Files\FlashGet Network\Flashget\InmediaInfo.ini
C:\Program Files\FlashGet Network\Flashget\JCCHS.INI
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\
0.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\1.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\10.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\11.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\12.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\13.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\14.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\15.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\16.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\17.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\18.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\19.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\2.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\20.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\21.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\3.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\4.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\5.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\6.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\7.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\8.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\9.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\nologin.bmp
C:\Program Files\FlashGet Network\Flashget\P2PCfg.ini
C:\Program Files\FlashGet Network\Flashget\p2spmgr.ini
C:\Program Files\FlashGet Network\Flashget\P4PClientInfo.ini
C:\Program Files\FlashGet Network\Flashget\p4spmgr.ini
C:\Program Files\FlashGet Network\Flashget\Profiles\config.dat
C:\Program Files\FlashGet Network\Flashget\Profiles\tasks.dat
C:\Program Files\FlashGet Network\Flashget\pup.dat
C:\Program Files\FlashGet Network\Flashget\StatInfo.ini
C:\Program Files\FlashGet Network\Flashget\transaction.log
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\admshare.dat
C:\WINDOWS\system32\dea0_z.dll
C:\WINDOWS\system32\taskmgr.com
.
((((((((((((((((((((((((( Files Created from 2008-09-18 to 2008-10-18 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-18 17:51 71,958,560 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-18 17:51 --------- d-----w C:\Documents and Settings\desktop\Application Data\DMCache
2008-10-18 17:50 844,376 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-18 14:46 --------- d-----w C:\Program Files\GVR
2008-10-18 14:27 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-10-18 14:25 --------- d-----w C:\Program Files\ACD Systems
2008-10-18 13:29 --------- d-----w C:\Program Files\Folder Lock
2008-10-18 11:57 --------- d-----w C:\Documents and Settings\desktop\Application Data\zzMicroWorld_Anti_Virus
2008-10-18 11:52 --------- d-----w C:\Documents and Settings\desktop\Application Data\cleaner
2008-10-18 10:46 --------- d-----w C:\Program Files\Spyware Doctor
2008-10-18 10:44 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-17 23:42 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-10-17 23:36 --------- d-----w C:\Program Files\Windows Live
2008-10-17 23:18 --------- d-----w C:\Program Files\Webroot
2008-10-17 23:18 --------- d-----w C:\Documents and Settings\desktop\Application Data\Webroot
2008-10-17 23:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Webroot
2008-10-16 22:14 --------- d-----w C:\Program Files\WinASO
2008-10-16 17:31 --------- d-----w C:\Program Files\Internet Cleaner
2008-10-16 13:37 --------- d-----w C:\Program Files\Steganos Internet Trace Destructor 7
2008-10-16 04:26 --------- d-----w C:\Documents and Settings\desktop\Application Data\Uniblue
2008-10-16 04:24 --------- d-----w C:\Program Files\Uniblue
2008-10-16 04:18 --------- d-----w C:\Program Files\Reference Assemblies
2008-10-16 03:49 --------- d-----w C:\Program Files\'Full Speed' Internet Booster + Performance Tests
2008-10-16 01:52 --------- dc-h--w C:\Documents and Settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2008-10-16 01:43 --------- d-----w C:\Program Files\Internet Download Manager
2008-10-16 00:21 --------- d-----w C:\Documents and Settings\desktop\Application Data\IDM
2008-10-16 00:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Tools
2008-10-16 00:04 --------- d-----w C:\Documents and Settings\desktop\Application Data\ACD Systems
2008-10-14 23:15 --------- d-----w C:\Documents and Settings\desktop\Application Data\Thinstall
2008-10-13 20:00 --------- d-----w C:\Documents and Settings\desktop\Application Data\CyberScrub
2008-10-13 13:47 2,015 ---h--r C:\WINDOWS\system32\drivers\hosts
2008-10-13 13:47 --------- d-----w C:\Program Files\RogueRemover PRO
2008-10-12 00:23 --------- d-----w C:\Program Files\Kaspersky Lab
2008-10-11 00:41 --------- d-----w C:\Program Files\Yahoo!
2008-10-11 00:41 --------- d-----w C:\Program Files\CCleaner
2008-10-10 19:06 --------- d-----w C:\Documents and Settings\desktop\Application Data\Apple Computer
2008-10-10 18:58 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-10 18:58 --------- d-----w C:\Program Files\QuickTime
2008-10-10 18:37 --------- d-----w C:\Documents and Settings\desktop\Application Data\Chic wma find
2008-10-10 14:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-10-09 04:21 --------- d-----w C:\Program Files\Error Repair Professional
2008-10-08 14:46 --------- d-----w C:\Program Files\Microsoft Windows OneCare Live
2008-10-08 11:36 --------- d-----w C:\Program Files\The Cleaner Free
2008-10-08 10:51 --------- d-----w C:\Documents and Settings\desktop\Application Data\PC Tools
2008-10-07 23:31 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-07 23:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-10-06 12:20 --------- d-----w C:\Program Files\Common Files\xing shared
2008-10-06 12:20 --------- d-----w C:\Program Files\Common Files\Real
2008-10-06 12:12 686,858 ----a-w C:\WINDOWS\unins000.exe
2008-10-06 12:09 --------- d-----w C:\Program Files\Real
2008-10-06 09:36 --------- d-----w C:\Program Files\Fake Webcam XP
2008-10-06 08:15 --------- d-----w C:\Program Files\Common Files\fwc
2008-10-06 08:13 --------- d-----w C:\Program Files\Common Files\delet
2008-10-06 04:06 --------- d-----w C:\Program Files\Ahead
2008-10-06 03:07 --------- d-----w C:\Documents and Settings\desktop\Application Data\GlarySoft
2008-10-06 02:45 --------- d-----w C:\Program Files\Glary Utilities
2008-10-05 12:46 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2008-10-05 12:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-05 10:48 --------- d-----w C:\Program Files\Ashampoo
2008-10-05 10:20 --------- d-----w C:\Program Files\The KMPlayer
2008-10-05 10:20 --------- d-----w C:\Program Files\Professional Registry Doctor
2008-10-05 03:32 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2008-10-05 03:06 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-10-04 22:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Winferno
2008-10-04 09:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-10-04 08:36 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-10-04 08:36 --------- d-----w C:\Program Files\Circle Developement
2008-10-04 07:51 --------- d-----w C:\Program Files\MessengerPlus! 3
2008-10-04 07:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-10-03 10:50 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-10-03 02:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-28 00:02 --------- d-----w C:\Program Files\Microsoft Works
2008-09-26 08:03 --------- d-----w C:\Program Files\3GP Player
2008-09-26 07:22 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-09-26 03:23 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-25 16:38 --------- d-----w C:\Program Files\Common Files\Panda Software
2008-09-25 16:08 --------- d-----w C:\Program Files\Panda Software
2008-09-25 16:08 --------- d-----w C:\Program Files\Paltalk Messenger
2008-09-25 16:08 --------- d-----w C:\Program Files\Google
2008-09-25 05:35 --------- d-----w C:\Program Files\Windows Doctor
2008-09-25 01:31 --------- d-----w C:\Program Files\Common Files\Webroot Shared
2008-09-24 16:59 5,376 ----a-w C:\WINDOWS\system32\drivers\MS1000.sys
2008-09-24 16:10 --------- d-----w C:\Program Files\Unlocker
2008-09-24 03:52 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-09-24 02:49 --------- d-----w C:\Documents and Settings\desktop\Application Data\CyberLink
2008-09-24 00:15 --------- d-----w C:\Program Files\Hotspot Shield
2008-09-23 23:02 --------- d-----w C:\Documents and Settings\desktop\Application Data\dvdcss
2008-09-23 21:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Okay Way Sixth Exit
2008-09-23 21:26 --------- d-----w C:\Program Files\Chic wma find
2008-09-23 20:53 --------- d-----w C:\Documents and Settings\desktop\Application Data\vlc
2008-09-23 20:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-09-23 20:29 --------- d-----w C:\Program Files\CyberLink
2008-09-23 20:21 --------- d-----w C:\Program Files\GRETECH
2008-09-23 20:17 --------- d-----w C:\Program Files\VideoLAN
2008-09-23 20:17 --------- d-----w C:\Documents and Settings\desktop\Application Data\Paltalk
2008-09-23 20:15 155,995 ----a-w C:\WINDOWS\java\Packages\4UDZBNL7.ZIP
2008-09-23 20:14 --------- d-----w C:\Program Files\القاموس
2008-09-23 20:09 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-23 19:54 --------- d-----w C:\Program Files\Intel
2008-09-23 19:47 --------- d-----w C:\Program Files\CONEXANT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Uniblue RegistryBooster 2009"="C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe" [08/26/2008 07:48 PM 2019624]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [10/15/2008 11:25 PM 2606512]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 11:34 AM 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [10/06/2008 03:20 PM 185872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnet3.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnet3[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnet3[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx3.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx30SP1setup.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx30SP1setup[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx30SP1setup[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx35.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx35setup.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx35setup[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx35setup[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx35[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx35[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx3setup.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx3setup[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx3setup[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx3[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx3[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx3_ia64.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx3_ia64[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx3_ia64[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx3_x64.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx3_x64[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx3_x64[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dotnetfx[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP1_ia64.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP1_ia64[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP1_ia64[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP1_x64.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP1_x64[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP1_x64[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP1_x86.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP1_x86[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP1_x86[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP2_ia64.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP2_ia64[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP2_ia64[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP2_x64.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP2_x64[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP2_x64[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP2_x86.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP2_x86[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx20SP2_x86[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx30SP1_x64.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx30SP1_x64[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx30SP1_x64[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx30SP1_x86.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx30SP1_x86[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx30SP1_x86[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx35_ia64.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx35_ia64[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx35_ia64[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx35_x64.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx35_x64[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx35_x64[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx35_x86.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx35_x86[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx35_x86[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx64.exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx64[1].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NetFx64[2].exe]
"Debugger"=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 is-7CDU5drv;is-7CDU5drv;C:\WINDOWS\system32\DRIVERS\42875000.sys [07/08/2008 02:54 PM 148496]
R1 is-BS5MCdrv;is-BS5MCdrv;C:\WINDOWS\system32\DRIVERS\71942541.sys [07/08/2008 02:54 PM 148496]
R1 is-UACA7drv;is-UACA7drv;C:\WINDOWS\system32\DRIVERS\38778091.sys [07/08/2008 02:54 PM 148496]
R2 wwEngineSvc;Window Washer Engine;C:\Program Files\Webroot\Washer\WasherSvc.exe [11/26/2007 02:47 PM 598856]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [01/11/2007 01:20 PM 194304]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [01/24/2008 12:25 AM 27136]
S0 TfFsMon;TfFsMon;C:\WINDOWS\system32\drivers\TfFsMon.sys [ ]
S0 TfSysMon;TfSysMon;C:\WINDOWS\system32\drivers\TfSysMon.sys [ ]
S1 is-0BSO4drv;is-0BSO4drv;C:\WINDOWS\system32\DRIVERS\13319238.sys [07/08/2008 02:54 PM 148496]
S1 is-F5RTVdrv;is-F5RTVdrv;C:\WINDOWS\system32\DRIVERS\19629752.sys [07/08/2008 02:54 PM 148496]
S1 is-IO3QQdrv;is-IO3QQdrv;C:\WINDOWS\system32\DRIVERS\
08784387.sys [07/08/2008 02:54 PM 148496]
S1 is-TT0JNdrv;is-TT0JNdrv;C:\WINDOWS\system32\DRIVERS\
07847223.sys [07/08/2008 02:54 PM 148496]
S3 TfNetMon;TfNetMon;C:\WINDOWS\system32\drivers\TfNetMon.sys [ ]
.
s of the 'Scheduled Tasks' folder
2008-10-18 C:\WINDOWS\Tasks\GlaryInitialize.job
- C:\Program Files\Glary Utilities\initialize.exe [09/17/2008 04:35 PM]
2008-10-05 C:\WINDOWS\Tasks\rpc.job
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe []
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-RunOnce-ITD7 - C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.net.com/
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O16 -: Microsoft XML Parser for Java - C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
.
------- File Associations -------
.
txtfile=C:\WINDOWS\notepad.exe %1
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-18 20:52:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 10/18/2008 20:53:28 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-18 17:53:23
Pre-Run: 23,734,022,144 bytes free
Post-Run: 23,660,650,496 bytes free
391 --- E O F --- 2008-10-16 01:23:32