السلام عليكم ورحمة الله وبركاته ...
بارك الله فيك أخوي
AbOdy هذا تقرير الاداة الاخيرة :
ComboFix 09-02-21.01 - ATEEK 02/24/2009 17:16:01.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1256.1.1025.18.758.313 [GMT 3:00]
Running from: c:\documents and settings\ATEEK\سطح المكتب\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\tmp.reg
.
((((((((((((((((((((((((( Files Created from 2009-01-24 to 2009-02-24 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-24 14:22 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-02-24 14:20 --------- d-----w c:\documents and settings\ATEEK\Application Data\DMCache
2009-02-24 14:18 540,704 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-02-24 14:18 3,976 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-02-24 14:18 20,468 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-02-24 14:18 2,347,552 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-02-24 13:47 --------- d-----w c:\documents and settings\ATEEK\Application Data\IDM
2009-02-24 12:38 --------- d-----w c:\program files\Conduit
2009-02-24 12:38 --------- d-----w c:\program files\AskTBar
2009-02-24 12:19 --------- d-----w c:\documents and settings\ATEEK\Application Data\CyberScrub
2009-02-24 12:16 --------- d-----w c:\documents and settings\ATEEK\Application Data\cleaner
2009-02-24 11:10 --------- d-----w c:\program files\Yahoo!
2009-02-24 11:08 --------- d-----w c:\program files\Jap
2009-02-23 09:04 --------- d-----w c:\program files\Registry Easy
2009-02-23 06:46 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-23 06:46 --------- d-----w c:\program files\JavaSoft
2009-02-23 06:42 --------- d-----w c:\documents and settings\ATEEK\Application Data\GTunnel
2009-02-21 09:51 --------- d-----w c:\program files\Reference Assemblies
2009-02-21 09:51 --------- d-----w c:\program files\MSBuild
2009-02-20 12:54 --------- d-----w c:\program files\SpeedBit Video Accelerator
2009-02-20 12:53 --------- d-----w c:\documents and settings\All Users\Application Data\Speedbit
2009-02-20 12:49 --------- d-----w c:\program files\SweetIM
2009-02-20 12:49 --------- d-----w c:\documents and settings\All Users\Application Data\SweetIM
2009-02-19 14:38 --------- d-----w c:\program files\Sweethearts 3D Screensaver
2009-02-19 14:34 --------- d-----w c:\program files\The Lost Watch 3D Screensaver
2009-02-19 14:31 --------- d-----w c:\program files\Ice Clock 3D Screensaver
2009-02-19 14:16 --------- d-----w c:\program files\3Planesoft Screensaver Manager
2009-02-18 14:46 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2009-02-18 09:51 --------- d-----w c:\documents and settings\All Users\Application Data\Winferno
2009-02-18 09:49 --------- d-----w c:\program files\Free Offers from Freeze.com
2009-02-18 09:47 --------- d-----w c:\documents and settings\All Users\Application Data\Wyyo
2009-02-18 04:08 --------- d-----w c:\documents and settings\ATEEK\Application Data\WNR
2009-02-17 16:30 --------- d-----w c:\documents and settings\ATEEK\Application Data\GPass-3
2009-02-12 15:54 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-11 10:54 --------- d-----w c:\documents and settings\ATEEK\Application Data\3
2009-02-10 10:52 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-04 17:59 --------- d-----w c:\documents and settings\ATEEK\Application Data\4
2009-02-04 17:50 --------- d-----w c:\documents and settings\ATEEK\Application Data\GPass
2009-02-04 11:13 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-04 11:13 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-02-03 04:38 --------- d-----w c:\program files\Internet Download Manager
2009-02-02 10:32 --------- d-----w c:\program files\LtUcx
2009-02-01 08:45 --------- d-----w c:\documents and settings\ATEEK\Application Data\Yahoo!
2009-02-01 08:44 --------- d-----w c:\documents and settings\ATEEK\Application Data\SlipStream
2009-01-29 19:10 65,541 ----a-w c:\windows\BricoPackUninst.cmd
2009-01-29 19:10 6,106 ----a-w c:\windows\BricoPackFoldersDelete.cmd
2009-01-29 12:18 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-27 14:33 --------- d-----w c:\program files\KingoOo Upload V3
2009-01-26 17:33 --------- d-----w c:\program files\EPSON
2009-01-26 17:33 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-26 17:33 --------- d-----w c:\documents and settings\All Users\Application Data\UDL
2009-01-26 14:24 --------- d-----w c:\program files\VisualBasic
2009-01-24 18:42 --------- d-----w c:\program files\TVPlayerClassic
2009-01-23 21:36 --------- d-----w c:\program files\Common Files\Nero
2009-01-23 21:13 --------- d-----w c:\program files\Nero
2009-01-23 21:10 --------- d-----w c:\program files\Windows Sidebar
2009-01-23 20:55 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2009-01-23 20:03 --------- d-----w c:\program files\DirectVobSub
2009-01-23 17:55 --------- d-----w c:\documents and settings\ATEEK\Application Data\Ashampoo
2009-01-23 17:54 --------- d-----w c:\documents and settings\All Users\Application Data\ashampoo
2009-01-23 17:53 --------- d-----w c:\program files\Ashampoo
2009-01-23 14:44 --------- d-----w c:\documents and settings\ATEEK\Application Data\Datalayer
2009-01-23 14:35 --------- d-----w c:\program files\Google
2009-01-23 11:29 --------- d-----w c:\documents and settings\ATEEK\Application Data\Nero
2009-01-23 03:51 --------- d-----w c:\program files\Microsoft Works
2009-01-21 14:20 --------- d-----w c:\program files\BandRich
2009-01-20 19:35 --------- d-----w c:\program files\Windows Live
2009-01-20 19:09 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2009-01-20 19:06 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2009-01-20 10:22 --------- d-----w c:\program files\MSXML 4.0
2009-01-19 20:38 --------- d-----w c:\program files\Kaspersky Lab
2009-01-19 20:37 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-01-19 20:04 73,216 ----a-w c:\windows\ST6UNST.EXE
2009-01-19 20:04 172,032 ------w c:\windows\Setup1.exe
2009-01-19 20:01 --------- d-----w c:\documents and settings\ATEEK\Application Data\PC Suite
2009-01-19 20:00 --------- d-----w c:\program files\Nokia
2009-01-19 20:00 --------- d-----w c:\program files\Common Files\PCSuite
2009-01-19 20:00 --------- d-----w c:\program files\Common Files\Nokia
2009-01-19 18:19 --------- d-----w c:\program files\3GP Player
2009-01-19 18:18 --------- d-----w c:\documents and settings\All Users\Application Data\GRETECH
2009-01-19 18:17 --------- d-----w c:\program files\GRETECH
2009-01-19 18:11 --------- d-----w c:\program files\Java
2009-01-19 13:23 --------- d-----w c:\documents and settings\ATEEK\Application Data\Winamp
2009-01-19 13:21 --------- d-----w c:\program files\Winamp
2009-01-19 13:02 --------- d-----w c:\program files\Real
2009-01-19 13:02 --------- d-----w c:\program files\Common Files\xing shared
2009-01-19 13:02 --------- d-----w c:\program files\Common Files\Real
2009-01-19 12:54 --------- d-----w c:\program files\All-in-1 Mobile Video Convert
2009-01-19 12:52 --------- d-----w c:\program files\Zoom Player
2009-01-19 12:50 --------- d-----w c:\program files\Windows Media Connect 2
2009-01-19 12:45 --------- d-----w c:\program files\Common Files\Java
2009-01-19 11:50 --------- d-----w c:\program files\Common Files\ACD Systems
2009-01-19 11:50 --------- d-----w c:\program files\ACD Systems
2009-01-19 11:50 --------- d-----w c:\documents and settings\All Users\Application Data\ACD Systems
2009-01-19 11:11 --------- d-----w c:\program files\microsoft frontpage
.
------- Sigcheck -------
04/14/2008 06:59 PM 974848 5320ea6507cfa8abc92caf91cd2fc8a5 c:\windows\explorer.exe
01/19/2009 09:13 PM 1655296 2fd48aaeaec9c891f72277bbe701f5db c:\windows\$NtServicePackUninstall$\explorer.exe
04/14/2008 06:59 PM 974848 5320ea6507cfa8abc92caf91cd2fc8a5 c:\windows\ServicePackFiles\i386\explorer.exe
01/19/2009 09:13 PM 66584 a7799dc80ab57384272e2179ef1237dd c:\windows\ServicePackFiles\i386\wuauclt.exe
01/19/2009 09:13 PM 66584 a7799dc80ab57384272e2179ef1237dd c:\windows\system32\wuauclt.exe
01/19/2009 09:13 PM 78360 0fb0036acea470cc670c4919fe53007f c:\windows\system32\dllcache\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [10/08/2008 12:22 PM 1172792]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [01/23/2009 05:35 PM 39408]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [02/03/2009 07:43 AM 2745776]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [08/26/2005 03:49 PM 860160]
"SpeedBitVideoAccelerator"="c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe" [02/20/2009 03:53 PM 2823784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [04/25/2005 05:32 AM 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [04/25/2005 05:29 AM 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [04/25/2005 05:32 AM 114688]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [01/19/2009 09:11 PM 136600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [01/19/2009 04:02 PM 185896]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [04/01/2008 09:49 PM 36352]
"DataLayer"="c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe" [09/06/2005 02:45 PM 820736]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [06/29/2005 03:29 PM 176128]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [08/24/2007 07:00 AM 33648]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [01/28/2009 04:57 PM 111928]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [02/10/2009 01:52 PM 206088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
c:\documents and settings\ATEEK\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
is-688M8.lnk - c:\documents and settings\ATEEK\«ل¥ ںéêè¢ \Virus Removal Tool\is-688M8\startup.exe [2009-02-23 65536]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R1 is-688M8drv;is-688M8drv;c:\windows\system32\drivers\78019896.sys [2009-02-23 148496]
R1 is-6D01Ddrv;is-6D01Ddrv;c:\windows\system32\drivers\30072513.sys [2009-02-22 148496]
R2 BandLuxe_Service;BandLuxe Service;c:\program files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe [2008-10-03 87264]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm --> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\drivers\br3gmdm.sys [2009-01-21 104192]
S3 FXDRV;FXDRV;\??\e:\fxdrv.sys --> e:\Fxdrv.sys [?]
S4 Wyyo Service;Wyyo Service;c:\documents and settings\All Users\Application Data\Wyyo\wyyo123.exe [2009-02-18 54752]
.
*******s of the 'Scheduled Tasks' folder
2009-02-24 c:\windows\Tasks\PCConfidential.job
- c:\program files\Winferno\PC Confidential\PCConfidential.exe []
2009-02-23 c:\windows\Tasks\Schedule Task Weekly.job
- c:\program files\Registry Easy\RE.exe [02/23/2009 07:44 AM]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MsnMsgr - ~c:\program files\Windows Live\Messenger\msnmsgr.exe
HKLM-Run-Device Detector - DevDetect.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-02-24 17:20:18
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
MsnMsgr = ~"c:\program files\Windows Live\Messenger\msnmsgr.exe" /background?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\.Default\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_Default.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\AppGPFault\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\CCSelect\9*JB0*خw]
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\Close\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\CriticalBatteryAlarm\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_CriticalBatteryAlarm.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\DeviceConnect\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_DeviceConnect.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\DeviceDisconnect\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_DeviceDisconnect.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\DeviceFail\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_DeviceFail.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\LowBatteryAlarm\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_LowBatteryAlarm.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\MailBeep\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_MailBeep.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\Maximize\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\MenuCommand\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\MenuPopup\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\Minimize\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\Open\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\PrintComplete\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\RestoreDown\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\RestoreUp\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\ShowBand\9*JB0*خw]
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\SystemAsterisk\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_SystemAsterisk.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\SystemExclamation\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_SystemExclamation.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\SystemExit\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_SystemExit.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\SystemHand\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_SystemHand.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\SystemNotification\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_SystemNotification.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\SystemQuestion\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\SystemStart\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_SystemStart.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\WindowsLogoff\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_WindowsLogoff.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\.Default\WindowsLogon\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_WindowsLogon.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\Explorer\ActivatingDocument\9*JB0*خw]
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\Explorer\BlockedPopup\9*JB0*خw]
@="Vista_BlockedPopup.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\Explorer\EmptyRecycleBin\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Vista_EmptyRecycleBin.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\Explorer\FeedDiscovered\9*JB0*خw]
@="Windows Feed Discovered.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\Explorer\MoveMenuItem\9*JB0*خw]
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\Explorer\Navigating\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Windows Navigation Start.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\Explorer\SearchProviderDiscovered\9*JB0*خw]
@=""
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\Explorer\SecurityBand\9*JB0*خw]
@="Vista_SecurityBand.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_ContactOnline\9*JB0*خw]
@="c:\\Program Files\\Messenger\\online.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewAlert\9*JB0*خw]
@="c:\\Program Files\\Messenger\\newalert.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewMail\9*JB0*خw]
@="c:\\Program Files\\Messenger\\newemail.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewMessage\9*JB0*خw]
@="c:\\Program Files\\Messenger\\type.wav"
[HKEY_USERS\S-1-5-21-839522115-1275210071-725345543-1004\AppEvents\Schemes\Names\9*JB0*خw]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="عتيق"
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe
c:\program files\Common Files\ACD Systems\EN\DevDetect.exe
c:\progra~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
c:\progra~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
c:\program files\Microsoft Office\Office12\ONENOTEM.EXE
c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
c:\windows\system32\wscntfy.exe
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 02/24/2009 17:25:51 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-24 14:25:46
Pre-Run: 30,918,561,792 bytes free
Post-Run: 30,879,162,368 bytes free
371 --- E O F --- 2009-02-18 14:46:53