هذا تقرير الفيكس
بس للمعلوميه ماحصل اللي ذكرته لي ماطلعت لي الا رساله وحده وضغطت نعم بس ماعاد التشغيل ...
ComboFix 08-10-31.02 - BURAQ 11/01/2008 4:16:00.2 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.525 [GMT -7:00]
Running from: C:\Documents and Settings\BURAQ\My Documents\Downloads\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-10-01 to 2008-11-01 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-01 09:17 4,364 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-11-01 09:17 247,328 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-11-01 09:17 2,080 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-11-01 09:17 1,268 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-28 20:49 --------- d-----w C:\Documents and Settings\BURAQ\Application Data\mpegprogram
2008-10-28 20:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\way rdr ford mpeg
2008-10-27 21:06 --------- d-----w C:\Documents and Settings\LocalService\Application Data\agi
2008-10-27 21:02 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-10-27 21:02 339,968 ----a-w C:\WINDOWS\system32\pythoncom25.dll
2008-10-27 21:02 2,117,632 ----a-w C:\WINDOWS\system32\python25.dll
2008-10-27 21:02 114,688 ----a-w C:\WINDOWS\system32\pywintypes25.dll
2008-10-22 18:38 98,304 ----a-w C:\WINDOWS\system32\viscomtran.dll
2008-10-22 10:58 --------- d-----w C:\Program Files\Google
2008-10-21 12:03 3,592 ----a-w C:\WINDOWS\system32\tmp.reg
2008-10-19 07:10 --------- d-----w C:\Documents and Settings\BURAQ\Application Data\CyberScrub
2008-10-19 07:09 --------- d-----w C:\Documents and Settings\BURAQ\Application Data\cleaner
2008-10-18 09:22 1,630,208 ----a-w C:\WINDOWS\system32\ULTRA SURF 9.9 BY OWL.exe
2008-10-15 16:57 332,800 ----a-w C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-15 03:18 --------- d-----w C:\Program Files\Netlog Video Tool
2008-10-15 02:06 --------- d-----w C:\Program Files\Netlog Photo Tool
2008-10-14 22:58 90,112 ----a-w C:\WINDOWS\DUMP5217.tmp
2008-10-07 01:24 --------- d-----w C:\Program Files\Mobily Connect Card
2008-10-04 02:55 --------- d-----w C:\Program Files\DCETools
2008-10-03 17:41 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2008-10-02 01:52 --------- d-----w C:\Documents and Settings\BURAQ\Application Data\CyberLink
2008-10-01 21:18 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-10-01 21:18 --------- d-----w C:\Program Files\Common Files\xing shared
2008-10-01 03:11 --------- d-----w C:\Program Files\Save Flash
2008-09-27 09:27 --------- d-----w C:\Program Files\LtUcx
2008-09-25 09:23 --------- d-----w C:\Program Files\iVocalize Web Conference 4
2008-09-25 07:17 --------- d-----w C:\Documents and Settings\BURAQ\Application Data\Media Player Classic
2008-09-22 08:42 --------- d-----w C:\Program Files\Stardock
2008-09-20 12:32 --------- d-----w C:\Program Files\Teorex
2008-09-19 15:12 --------- d-----w C:\Program Files\MosaicCreator
2008-09-17 09:59 --------- d-----w C:\Program Files\MSXML 6.0
2008-09-16 16:26 1,332,197 ----a-w C:\WINDOWS\system32\pythondll.zip
2008-09-16 13:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-09-16 10:12 --------- d-----w C:\Program Files\Circle Developement
2008-09-16 06:02 91,700 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-09-16 06:02 85,860 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-09-16 06:02 --------- d-----w C:\Program Files\Kaspersky Lab
2008-09-16 06:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-16 06:01 344,064 ----a-w C:\WINDOWS\system32\dkll.dll
2008-09-16 06:01 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-09-16 06:01 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-09-16 06:01 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-09-16 06:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-16 06:00 --------- d-----w C:\Program Files\Ozone
2008-09-16 06:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-09-16 05:59 --------- d-----w C:\Program Files\Windows Live
2008-09-16 05:59 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-16 05:59 --------- d-----w C:\Program Files\CyberLink
2008-09-16 05:58 --------- d-----w C:\Program Files\MSN Messenger
2008-09-16 05:58 --------- d-----w C:\Program Files\Macromedia
2008-09-16 05:57 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-09-16 05:57 --------- d-----w C:\Documents and Settings\BURAQ\Application Data\IDM
2008-09-16 05:57 --------- d-----w C:\Documents and Settings\BURAQ\Application Data\DMCache
2008-09-16 05:56 --------- d-----w C:\Program Files\Internet Download Manager
2008-09-16 05:56 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-16 05:56 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-09-16 05:56 --------- d-----w C:\Program Files\ACD Systems
2008-09-16 05:56 --------- d-----w C:\Documents and Settings\BURAQ\Application Data\ACD Systems
2008-09-16 05:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-09-16 05:55 --------- d-----w C:\Program Files\GRETECH
2008-09-16 05:55 --------- d-----w C:\Documents and Settings\BURAQ\Application Data\GRETECH
2008-09-16 05:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\GRETECH
2008-09-16 05:54 --------- d-----w C:\Program Files\Nokia
2008-09-16 05:54 --------- d-----w C:\Program Files\Java
2008-09-16 05:54 --------- d-----w C:\Program Files\Hotspot Shield
2008-09-16 05:54 --------- d-----w C:\Program Files\Common Files\Nokia
2008-09-16 05:54 --------- d-----w C:\Program Files\Common Files\Java
2008-09-16 05:53 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-09-16 05:53 --------- d-----w C:\Program Files\Nero
2008-09-16 05:53 --------- d-----w C:\Program Files\Common Files\Ahead
2008-09-16 05:52 --------- d-----w C:\Program Files\Real
2008-09-16 05:52 --------- d-----w C:\Program Files\Common Files\Real
2008-09-16 05:46 5 ----a-w C:\WINDOWS\system32\drivers\DELL_XPS_Dell 500 .MRK
2008-09-16 05:46 5 ----a-w C:\WINDOWS\system32\drivers\1028_DELL_XPS_Dell 500 .MRK
2008-09-16 05:42 --------- d-----w C:\Program Files\Marvell
2008-09-16 05:41 --------- d-----w C:\Documents and Settings\BURAQ\Application Data\TMP
2008-09-16 05:39 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\Intel
2008-09-16 05:39 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Intel
2008-09-16 05:39 --------- d-----w C:\Documents and Settings\BURAQ\Application Data\Intel
2008-09-16 05:38 21,393 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-09-16 05:38 21,393 ----a-w C:\WINDOWS\AegisP.sys
2008-09-16 05:38 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Intel
2008-09-16 05:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intel
2008-09-16 05:33 --------- d-----w C:\Program Files\WIDCOMM
2008-09-16 05:31 --------- d-----w C:\Program Files\CONEXANT
2008-09-16 05:28 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-09-16 05:28 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_Apfiltr_01005.Wdf
2008-09-16 05:28 --------- d-----w C:\Program Files\DellTPad
2008-09-16 05:27 --------- d-----w C:\Program Files\DIFX
2008-09-16 05:25 --------- d-----w C:\Program Files\Intel
2008-09-16 05:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-16 05:23 --------- d-----w C:\Program Files\SigmaTel
2008-09-16 05:23 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-16 05:23 --------- d-----w C:\Documents and Settings\BURAQ\Application Data\Dell
2008-09-16 05:22 --------- d-----w C:\Documents and Settings\BURAQ\Application Data\InstallShield
2008-09-16 05:21 --------- d-----w C:\Program Files\Dell
.
كود:
<pre>
----a-w 518,481 2002-01-05 18:00:26 C:\Documents and Settings\BURAQ\Desktop\مجموعة العاب\أجمل ألعاب الفلاش\لعبة مبنى التجارة .exe
</pre>
(((((((((((((((((((((((((((((
snapshot@Tue 10-21-2008_ 3.25.23.79 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-15 16:53:28 339,456 ------w C:\WINDOWS\$hf_mig$\KB958644\SP2QFE\netapi32.dll
+ 2008-10-15 16:34:24 337,408 ------w C:\WINDOWS\$hf_mig$\KB958644\SP3GDR\netapi32.dll
+ 2008-10-15 16:25:54 339,456 ------w C:\WINDOWS\$hf_mig$\KB958644\SP3QFE\netapi32.dll
+ 2007-11-30 11:18:52 17,272 ------w C:\WINDOWS\$hf_mig$\KB958644\spmsg.dll
+ 2007-11-30 11:18:52 231,288 ------w C:\WINDOWS\$hf_mig$\KB958644\spuninst.exe
+ 2007-11-30 11:18:52 26,488 ------w C:\WINDOWS\$hf_mig$\KB958644\update\spcustom.dll
+ 2007-11-30 11:18:52 755,576 ------w C:\WINDOWS\$hf_mig$\KB958644\update\update.exe
+ 2007-11-30 11:18:52 382,840 ------w C:\WINDOWS\$hf_mig$\KB958644\update\updspapi.dll
+ 2004-08-04 04:56:46 332,288 ------w C:\WINDOWS\$NtUninstallKB958644$\netapi32.dll
+ 2007-11-30 11:18:52 231,288 ------w C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe
+ 2007-11-30 11:18:52 382,840 ------w C:\WINDOWS\$NtUninstallKB958644$\spuninst\updspapi.dll
+ 2007-08-02 18:31:32 360,320 ----a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.1\MsnPUpld.dll
+ 2007-08-02 18:31:32 67,456 ----a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.1\PURen-us.dll
+ 2007-08-02 18:31:32 67,456 ----a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.1\PURen-ww.dll
+ 2008-09-08 19:58:46 204,800 ----a-w C:\WINDOWS\Downloaded Program Files\InstallerControl.dll
- 2008-10-20 18:27:18 331,776 ----a-w C:\WINDOWS\system32\agsaama.dll
+ 2008-10-22 18:39:00 331,776 ----a-w C:\WINDOWS\system32\agsaama.dll
- 2008-10-20 18:27:18 538,624 ----a-w C:\WINDOWS\system32\agsaamb.dll
+ 2008-10-22 18:39:00 538,624 ----a-w C:\WINDOWS\system32\agsaamb.dll
- 2008-10-20 18:27:18 372,736 ----a-w C:\WINDOWS\system32\agsaamc.dll
+ 2008-10-22 18:39:00 372,736 ----a-w C:\WINDOWS\system32\agsaamc.dll
- 2008-10-20 18:27:18 544,256 ----a-w C:\WINDOWS\system32\agsaamd.dll
+ 2008-10-22 18:39:02 544,256 ----a-w C:\WINDOWS\system32\agsaamd.dll
- 2008-10-20 18:27:18 551,424 ----a-w C:\WINDOWS\system32\agsaame.dll
+ 2008-10-22 18:39:02 551,424 ----a-w C:\WINDOWS\system32\agsaame.dll
- 2008-10-20 18:27:18 753,664 ----a-w C:\WINDOWS\system32\agsaamg.dll
+ 2008-10-22 18:39:02 753,664 ----a-w C:\WINDOWS\system32\agsaamg.dll
- 2008-10-20 18:27:18 626,688 ----a-w C:\WINDOWS\system32\agsaamh.dll
+ 2008-10-22 18:39:02 626,688 ----a-w C:\WINDOWS\system32\agsaamh.dll
- 2008-10-20 18:27:18 90,112 ----a-w C:\WINDOWS\system32\agsaami.dll
+ 2008-10-22 18:39:02 90,112 ----a-w C:\WINDOWS\system32\agsaami.dll
- 2008-10-20 18:27:18 2,846,720 ----a-w C:\WINDOWS\system32\agsaamj.dll
+ 2008-10-22 18:39:04 2,846,720 ----a-w C:\WINDOWS\system32\agsaamj.dll
- 2008-10-20 18:27:16 778,240 ----a-w C:\WINDOWS\system32\ALOAudioCompress2.dll
+ 2008-10-22 18:38:58 778,240 ----a-w C:\WINDOWS\system32\ALOAudioCompress2.dll
- 2008-10-20 18:27:16 2,846,720 ----a-w C:\WINDOWS\system32\ALOAudioCompress3.dll
+ 2008-10-22 18:39:00 2,846,720 ----a-w C:\WINDOWS\system32\ALOAudioCompress3.dll
- 2008-10-20 18:27:16 877,568 ----a-w C:\WINDOWS\system32\ALOAudioFile2.dll
+ 2008-10-22 18:39:00 877,568 ----a-w C:\WINDOWS\system32\ALOAudioFile2.dll
- 2008-10-20 18:27:16 90,112 ----a-w C:\WINDOWS\system32\ALOAudioFormatSettings3.dll
+ 2008-10-22 18:39:00 90,112 ----a-w C:\WINDOWS\system32\ALOAudioFormatSettings3.dll
- 2008-10-20 18:27:16 382,464 ----a-w C:\WINDOWS\system32\ALOAVIFile.dll
+ 2008-10-22 18:39:00 382,464 ----a-w C:\WINDOWS\system32\ALOAVIFile.dll
- 2008-10-20 18:27:16 249,856 ----a-w C:\WINDOWS\system32\ALOQuickTimeFile.dll
+ 2008-10-22 18:39:00 249,856 ----a-w C:\WINDOWS\system32\ALOQuickTimeFile.dll
- 2008-10-20 18:27:16 780,288 ----a-w C:\WINDOWS\system32\ALOVideoCompress.dll
+ 2008-10-22 18:39:00 780,288 ----a-w C:\WINDOWS\system32\ALOVideoCompress.dll
- 2008-10-20 18:27:16 495,104 ----a-w C:\WINDOWS\system32\ALOVideoCoreM.dll
+ 2008-10-22 18:39:02 495,104 ----a-w C:\WINDOWS\system32\ALOVideoCoreM.dll
- 2008-10-20 18:27:16 188,416 ----a-w C:\WINDOWS\system32\ALOVideoFile.dll
+ 2008-10-22 18:39:02 188,416 ----a-w C:\WINDOWS\system32\ALOVideoFile.dll
- 2008-10-20 18:27:16 403,968 ----a-w C:\WINDOWS\system32\ALOWMAFile2.dll
+ 2008-10-22 18:39:02 403,968 ----a-w C:\WINDOWS\system32\ALOWMAFile2.dll
- 2008-10-20 18:27:16 215,552 ----a-w C:\WINDOWS\system32\ALOWMVFile.dll
+ 2008-10-22 18:39:02 215,552 ----a-w C:\WINDOWS\system32\ALOWMVFile.dll
- 2008-10-20 18:27:16 1,245,184 ----a-w C:\WINDOWS\system32\bkll.dll
+ 2008-10-22 18:39:02 1,245,184 ----a-w C:\WINDOWS\system32\bkll.dll
- 2008-09-16 06:01:04 18,595,840 ----a-w C:\WINDOWS\system32\coredata.dll
+ 2008-10-22 18:38:48 18,595,840 ----a-w C:\WINDOWS\system32\coredata.dll
- 2004-08-04 04:56:46 332,288 ----a-w C:\WINDOWS\system32\netapi32.dll
+ 2008-10-15 16:57:56 332,800 ----a-w C:\WINDOWS\system32\netapi32.dll
- 2008-09-16 06:01:04 1,128,128 ----a-w C:\WINDOWS\system32\NMSDVDXU.dll
+ 2008-10-22 18:38:48 1,128,128 ----a-w C:\WINDOWS\system32\NMSDVDXU.dll
+ 2008-04-14 00:12:36 7,680 ----a-w C:\WINDOWS\system32\spdwnwxp.exe
- 2006-10-09 04:51:14 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2007-08-11 03:46:18 26,488 ----a-w C:\WINDOWS\system32\spupdsvc.exe
- 2008-09-16 06:01:04 90,112 ----a-w C:\WINDOWS\system32\ssvideo.dll
+ 2008-10-22 18:38:48 90,112 ----a-w C:\WINDOWS\system32\ssvideo.dll
- 2008-09-16 06:01:04 19,456 ----a-w C:\WINDOWS\system32\videocore.dll
+ 2008-10-22 18:38:48 19,456 ----a-w C:\WINDOWS\system32\videocore.dll
- 2008-09-16 06:01:06 18,599,936 ----a-w C:\WINDOWS\system32\videoencode.dll
+ 2008-10-22 18:38:50 18,599,936 ----a-w C:\WINDOWS\system32\videoencode.dll
- 2008-09-16 06:01:06 452,608 ----a-w C:\WINDOWS\system32\videoformat.dll
+ 2008-10-22 18:38:52 452,608 ----a-w C:\WINDOWS\system32\videoformat.dll
- 2008-09-16 06:01:06 6,963,712 ----a-w C:\WINDOWS\system32\videotrans.dll
+ 2008-10-22 18:38:54 6,963,712 ----a-w C:\WINDOWS\system32\videotrans.dll
- 2008-09-16 06:01:06 1,462,272 ----a-w C:\WINDOWS\system32\viscom3gpenc.dll
+ 2008-10-22 18:38:54 1,462,272 ----a-w C:\WINDOWS\system32\viscom3gpenc.dll
- 2008-09-16 06:01:06 1,454,080 ----a-w C:\WINDOWS\system32\viscomamrenc.dll
+ 2008-10-22 18:38:54 1,454,080 ----a-w C:\WINDOWS\system32\viscomamrenc.dll
- 2008-09-16 06:01:06 94,208 ----a-w C:\WINDOWS\system32\viscomaudiodata.dll
+ 2008-10-22 18:38:54 94,208 ----a-w C:\WINDOWS\system32\viscomaudiodata.dll
- 2008-09-16 06:01:06 110,592 ----a-w C:\WINDOWS\system32\viscomaudioencoder.dll
+ 2008-10-22 18:38:54 110,592 ----a-w C:\WINDOWS\system32\viscomaudioencoder.dll
- 2008-09-16 06:01:08 18,628,608 ----a-w C:\WINDOWS\system32\viscomavi.dll
+ 2008-10-22 18:38:56 18,628,608 ----a-w C:\WINDOWS\system32\viscomavi.dll
- 2008-09-16 06:01:08 1,462,272 ----a-w C:\WINDOWS\system32\viscomdata1.dll
+ 2008-10-22 18:38:56 1,462,272 ----a-w C:\WINDOWS\system32\viscomdata1.dll
- 2008-09-16 06:01:08 1,454,080 ----a-w C:\WINDOWS\system32\viscomdata2.dll
+ 2008-10-22 18:38:56 1,454,080 ----a-w C:\WINDOWS\system32\viscomdata2.dll
- 2008-09-16 06:01:08 1,470,464 ----a-w C:\WINDOWS\system32\viscomdata3.dll
+ 2008-10-22 18:38:56 1,470,464 ----a-w C:\WINDOWS\system32\viscomdata3.dll
- 2008-09-16 06:01:08 118,784 ----a-w C:\WINDOWS\system32\viscomflvdec.dll
+ 2008-10-22 18:38:56 118,784 ----a-w C:\WINDOWS\system32\viscomflvdec.dll
- 2008-09-16 06:01:08 1,462,272 ----a-w C:\WINDOWS\system32\viscomflvenc.dll
+ 2008-10-22 18:38:58 1,462,272 ----a-w C:\WINDOWS\system32\viscomflvenc.dll
- 2008-09-16 06:01:08 86,016 ----a-w C:\WINDOWS\system32\viscomframe.dll
+ 2008-10-22 18:38:58 86,016 ----a-w C:\WINDOWS\system32\viscomframe.dll
- 2008-09-16 06:01:08 1,470,464 ----a-w C:\WINDOWS\system32\viscomm4aenc.dll
+ 2008-10-22 18:38:58 1,470,464 ----a-w C:\WINDOWS\system32\viscomm4aenc.dll
- 2008-09-16 06:01:08 602,112 ----a-w C:\WINDOWS\system32\viscomqtde.dll
+ 2008-10-22 18:38:58 602,112 ----a-w C:\WINDOWS\system32\viscomqtde.dll
- 2008-09-16 06:01:08 147,456 ----a-w C:\WINDOWS\system32\viscomqtenc.dll
+ 2008-10-22 18:38:58 147,456 ----a-w C:\WINDOWS\system32\viscomqtenc.dll
- 2008-09-16 06:01:08 118,784 ----a-w C:\WINDOWS\system32\viscomrmenc.dll
+ 2008-10-22 18:38:58 118,784 ----a-w C:\WINDOWS\system32\viscomrmenc.dll
- 2008-09-16 06:01:08 48,640 ----a-w C:\WINDOWS\system32\viscomsamplerate.dll
+ 2008-10-22 18:38:58 48,640 ----a-w C:\WINDOWS\system32\viscomsamplerate.dll
- 2008-09-16 06:01:08 81,920 ----a-w C:\WINDOWS\system32\viscomwave.dll
+ 2008-10-22 18:38:58 81,920 ----a-w C:\WINDOWS\system32\viscomwave.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 09:56 PM 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [09/15/2008 10:57 PM 932864]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [01/19/2007 12:55 PM 5674352]
"Netlog Music Tool"="C:\Program Files\Netlog Music Tool\NetlogMusicTool.exe" [N/A]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [10/26/2008 11:59 PM 171448]
"LoudSkip"="C:\DOCUME~1\BURAQ\APPLIC~1\MPEGPR~1\denttitleidle.exe" [10/28/2008 01:48 PM 585728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [12/10/2007 06:06 PM 1228800]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [05/10/2007 10:22 AM 405504]
"Apoint"="C:\Program Files\DellTPad\Apoint.exe" [07/02/2007 01:29 PM 159744]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [07/25/2007 04:32 PM 823296]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [07/25/2007 04:30 PM 974848]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [09/05/2007 05:13 PM 141848]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [09/05/2007 05:13 PM 166424]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [09/05/2007 05:13 PM 137752]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [09/15/2008 10:54 PM 77824]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [12/07/2005 10:57 PM 30208]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [04/13/2006 11:09 AM 49152]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [10/01/2008 02:18 PM 185872]
"Ford mpeg road draw"="C:\Documents and Settings\All Users\Application Data\way rdr ford mpeg\poll thunk.exe" [11/01/2008 03:59 AM 1657856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/03/2004 09:56 PM 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-05-17 568176]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-09-22 113664]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Macromedia\\Flash MX\\Flash.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\winks\\mcoinstall.exe"=
"C:\\Program Files\\Mobily Connect Card\\Mobily Connect Card.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [12/13/2007 01:28 PM 24592]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [06/07/2007 11:52 PM 27136]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da45091f-8f92-11dd-83bd-001fe1dba3b1}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{def9b946-940e-11dd-83ce-001fe1dba3b1}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fededd88-a11d-11dd-8408-001f3c577c2d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BD195C73-48CA-FFB7-61FD-038F0AAB384B}]
C:\DOCUME~1\BURAQ\LOCALS~1\Temp\svchost.exe
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\BURAQ\Application Data\Mozilla\Firefox\Profiles\fw8yq5jt.default\
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava11.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava12.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava13.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava14.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava32.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npoji610.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-01 04:19:09
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/01/2008 4:20:21
ComboFix-quarantined-files.txt 2008-11-01 11:20:20
ComboFix2.txt 2008-10-21 10:26:02
Pre-Run: 10,951,507,968 bytes free
Post-Run: 11,048,009,728 bytes free
327 --- E O F --- 2008-10-25 21:38:48