اخي هشام
مشكور علي اهتمامك
وشاكر جدا علي متباعتك
وده تقرير الكومبو فيكس
ComboFix 09-02-24.02 - saad 02/25/2009 13:42:59.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.1015.59 [GMT 2:00]
Running from: c:\documents and settings\saad\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning enabled* (Updated)
FW: Kaspersky Internet Security *enabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\autoscan.dll
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\kakle.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2009-01-25 to 2009-02-25 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-25 12:15 32 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-02-25 12:15 32 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-02-25 12:15 32 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-02-25 12:15 32 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-02-25 09:45 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-25 09:45 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-25 09:45 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-02-20 15:20 --------- d-----w c:\program files\Kaspersky Lab
2009-02-20 15:20 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-02-20 14:56 --------- d-----w c:\program files\SUPERAntiSpyware
2009-02-20 14:56 --------- d-----w c:\documents and settings\saad\Application Data\SUPERAntiSpyware.com
2009-02-20 14:56 --------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-02-20 14:55 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-02-19 17:39 --------- d-----w c:\documents and settings\saad\Application Data\InterTrust
2009-02-19 17:38 --------- d-----w c:\program files\Readiris Pro 9
2009-02-15 05:37 --------- d-----w c:\documents and settings\saad\Application Data\EAST Technologies
2009-02-15 05:36 --------- d-----w c:\program files\East-Tec Eraser 2009
2009-02-14 10:14 --------- d-----w c:\documents and settings\LocalService\Application Data\TeamViewer
2009-02-14 04:58 --------- d-----w c:\program files\TeamViewer3
2009-02-14 04:33 --------- d-----w c:\program files\TeamViewer
2009-02-14 04:33 --------- d-----w c:\documents and settings\saad\Application Data\TeamViewer
2009-02-13 21:59 --------- d-----w c:\program files\Error Repair Professional
2009-02-12 06:54 --------- d-----w c:\program files\Boost Windows
2009-02-12 06:51 --------- d-----w c:\documents and settings\saad\Application Data\Boost Windows
2009-02-12 06:51 --------- d-----w c:\documents and settings\All Users\Application Data\TEMP
2009-02-12 00:36 --------- d-----w c:\documents and settings\saad\Application Data\Media Player Classic
2009-02-12 00:35 --------- d-----w c:\program files\Common Files\Real
2009-02-12 00:35 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-02-12 00:33 --------- d-----w c:\program files\K-Lite Codec Pack
2009-02-11 05:04 --------- d-----w c:\documents and settings\saad\Application Data\IDM
2009-02-10 04:08 --------- d-----w c:\program files\netcut
2009-02-10 00:41 --------- d-----w c:\documents and settings\saad\Application Data\CyberScrub
2009-02-10 00:40 --------- d-----w c:\documents and settings\saad\Application Data\cleaner
2009-02-08 17:04 --------- d-----w c:\documents and settings\saad\Application Data\EbkReader
2009-02-07 02:08 --------- d-----w c:\program files\DAEMON Tools
2009-02-07 02:07 96,384 ----a-w c:\windows\system32\drivers\sptddrv1.sys
2009-02-07 02:07 611,064 ----a-w c:\windows\system32\drivers\sptd.sys
2009-02-03 04:12 196,608 ----a-w c:\windows\system32\maag.dll
2009-02-03 04:12 1,986,560 ----a-w c:\windows\system32\akll.dll
2009-02-03 04:12 1,245,184 ----a-w c:\windows\system32\bkll.dll
2009-02-03 04:12 1,212,416 ----a-w c:\windows\system32\ckll.dll
2009-02-03 04:11 90,112 ----a-w c:\windows\system32\agsaami.dll
2009-02-03 04:11 610,304 ----a-w c:\windows\system32\agsaamg.dll
2009-02-03 04:11 372,736 ----a-w c:\windows\system32\agsaamc.dll
2009-02-03 04:11 2,535,424 ----a-w c:\windows\system32\agsaamj.dll
2009-01-31 22:29 113,536 ----a-w c:\documents and settings\saad\Application Data\GDIPFONTCACHEV1.DAT
2009-01-31 19:16 --------- d-----w c:\program files\FLV Player
2009-01-31 17:46 --------- d-----w c:\program files\Ringz Studio
2009-01-30 23:25 --------- d-----w c:\documents and settings\saad\Application Data\skypePM
2009-01-30 23:22 --------- d-----w c:\program files\Skype
2009-01-30 23:22 --------- d-----w c:\program files\Google
2009-01-30 23:22 --------- d-----w c:\program files\Common Files\Skype
2009-01-30 23:22 --------- d-----w c:\documents and settings\saad\Application Data\Skype
2009-01-30 23:21 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-01-30 20:56 --------- d-----w c:\program files\ColorSoft
2009-01-30 17:03 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2009-01-30 16:57 --------- d-----w c:\program files\MSN Messenger
2009-01-30 16:55 --------- d-----w c:\program files\Windows Live
2009-01-30 13:38 --------- d-----w c:\documents and settings\saad\Application Data\vlc
2009-01-30 13:37 --------- d-----w c:\program files\VideoLAN
2009-01-29 19:49 360,192 ----a-w c:\windows\system32\TuneUpDefragService.exe
2009-01-29 09:23 603,904 ----a-w c:\windows\system32\TUProgSt.exe
2009-01-29 09:23 --------- d-sh--w c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-01-29 09:23 --------- d-----w c:\program files\TuneUp Utilities 2009
2009-01-28 12:26 --------- d-----w c:\program files\Kelk 2000
2009-01-28 07:16 --------- d-----w c:\program files\Microsoft
2009-01-28 05:48 --------- d-----w c:\program files\Common Files\Windows Live
2009-01-28 04:57 --------- d-----w c:\program files\Reference Assemblies
2009-01-28 04:57 --------- d-----w c:\program files\MSBuild
2009-01-27 08:30 --------- d-----w c:\program files\DustBuster
2009-01-26 17:34 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2009-01-25 15:51 --------- d-----w c:\program files\ACD Systems
2009-01-25 15:51 --------- d-----w c:\documents and settings\All Users\Application Data\ACD Systems
2009-01-25 15:50 10,368 ----a-w c:\windows\system32\drivers\pfc.sys
2009-01-25 15:49 --------- d-----w c:\program files\WinPcap
2008-12-12 17:01 3,067,904 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\dllcache\srv.sys
2008-12-02 20:37 49,480 ----a-w c:\windows\system32\sirenacm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/14/2008 02:12 AM 15360]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [01/19/2007 12:54 PM 5674352]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [08/30/2007 05:43 PM 4670704]
"Eraser RiskMonitor"="c:\program files\East-Tec Eraser 2009\Launch.exe" [11/03/2008 03:25 PM 44192]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [03/02/2007 03:26 PM 149040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Persistence"="c:\windows\system32\igfxpers.exe" [11/08/2007 10:56 AM 137752]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [08/04/2004 04:07 AM 208952]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [11/08/2007 10:56 AM 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [11/08/2007 10:56 AM 166424]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [02/21/2009 01:33 AM 201992]
"StormCodec_Helper"="c:\program files\Ringz Studio\Storm Codec\StormSet.exe" [11/26/2006 08:30 PM 97357]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [03/02/2007 03:46 PM 153136]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [05/11/2005 11:12 PM 49152]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [09/14/2006 10:09 PM 157592]
"AntiARPStandalone"="c:\program files\ColorSoft\AntiARP\AntiARP.exe" [11/22/2008 12:10 PM 7979520]
"SkyTel"="SkyTel.EXE" [10/11/2007 06:04 AM 1826816 c:\windows\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [10/25/2007 06:57 AM 16855552 c:\windows\RTHDCPL.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NewShortcut3.lnk - c:\windows\Twain_32\CA561B\SnapDetectB.exe [2009-01-28 65536]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-06-19 113664]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [05/13/2008 09:13 AM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
12/22/2008 11:05 AM 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\I:\
0autocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"raVe"=
"Driver32"=
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\TeamViewer3\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-12-22 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-12-22 55024]
R2 AntiARPClientLoader;AntiARP Client Loader;c:\program files\ColorSoft\AntiARP\AntiARPClientLoader.exe [2007-10-17 40960]
R2 AntiArpNdisProt;AntiARP NDIS Protocol Driver;c:\windows\system32\drivers\AntiArpNdisProt.sys [2007-04-18 21120]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-01-29 603904]
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;c:\windows\system32\drivers\l251x86.sys [2008-06-19 30720]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-03-25 24592]
R3 xAntiArp;xAntiArpSpoof Service;c:\windows\system32\drivers\xAntiArp.sys [2008-11-22 311040]
S3 CA561B;ICatch 561B PC CAMERA;c:\windows\system32\drivers\spca561b.sys [2009-01-28 241280]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-22 7408]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d039229f-efe5-11dd-b3b8-001e8ca1471d}]
\Shell\1\command - spoclv.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL spoclv.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d03922a0-efe5-11dd-b3b8-001e8ca1471d}]
\Shell\1\command - spoclv.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL spoclv.exe
.
*******s of the 'Scheduled Tasks' folder
2009-02-25 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [12/11/2008 09:36 PM]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-SystemInit - (no file)
HKLM-Run-Karen - (no file)
HKLM-Run-raVe - (no file)
HKLM-Run-Win32BaseServiceMOD - (no file)
HKLM-Run-startIE - (no file)
HKLM-RunServices-raVe - (no file)
HKLM-RunServices-Driver32 - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.eg/
uInternet Connection Wizard,ShellNext =
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
TCP: {138E0996-8B43-46A1-8427-A3ADCA8A8DA3} = 4.2.2.2,4.2.2.3
FF - ProfilePath - c:\documents and settings\saad\Application Data\Mozilla\Firefox\Profiles\4bdfl2vg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.eg/
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\saad\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: *******.notify.interval - 600000
FF - user.js: *******.max.tokenizing.time - 1800000
FF - user.js: *******.switch.threshold - 600000
.
.
------- File Associations -------
.
txtfile=NOTEPAD %1
vbefile\shell\edit\command=c:\windows\Notepad.exe %1
vbsfile\shell\edit\command=c:\windows\Notepad.exe %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-02-25 14:21:23
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3b97b5d4-41a8-42d6-b7aa-0d2f5dda2bce}]
@Denied: (Full) (Everyone)
"Model"=dword:00000029
"Therad"=dword:00000003
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):68,4f,be,9e,c8,2b,ef,c4,db,33,df,19,64,b9,ac,7c,60,fe,06,dd,9f,
14,62,4e,a6,99,d9,af,1a,a5,93,a3,d6,0e,2a,34,aa,fa,ff,f6,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):3d,5c,9f,d3,53,f7,db,08,98,18,2f,8c,a7,8b,8c,76,54,8a,e1,f5,42,
6d,ff,25,69,53,92,e8,9b,1e,8e,19,5f,ef,b2,0c,99,ba,66,45,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f19e9405-16ec-449e-beb8-ffaac8217aaf}]
@Denied: (Full) (Everyone)
"Model"=dword:00000028
"Therad"=dword:0000000f
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1160)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\klogon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\crypserv.exe
c:\program files\FolderSize\FolderSizeSvc.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\East-Tec Eraser 2009\etRiskMon.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\windows\system32\wscntfy.exe
c:\program files\Mozilla Firefox\firefox.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Completion time: 02/25/2009 14:23:08 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-25 12:23:04
Pre-Run: 11,920,801,792 bytes free
Post-Run: 12,038,209,536 bytes free
302 --- E O F --- 2009-02-25 09:08:47
وده تقرير الهاي جاك
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:49:53, on 25/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ColorSoft\AntiARP\AntiARPClientLoader.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\East-Tec Eraser 2009\etRiskMon.exe
C:\WINDOWS\Twain_32\CA561B\SnapDetectB.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Documents and Settings\saad\Desktop\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AntiARPStandalone] C:\Program Files\ColorSoft\AntiARP\AntiARP.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Eraser RiskMonitor] "C:\Program Files\East-Tec Eraser 2009\Launch.exe" "C:\Program Files\East-Tec Eraser 2009\etRiskMon.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: NewShortcut3.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{138E0996-8B43-46A1-8427-A3ADCA8A8DA3}: NameServer = 4.2.2.2,4.2.2.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{138E0996-8B43-46A1-8427-A3ADCA8A8DA3}: NameServer = 4.2.2.2,4.2.2.3
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AntiARP Client Loader (AntiARPClientLoader) - Unknown owner - C:\Program Files\ColorSoft\AntiARP\AntiARPClientLoader.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
--
End of file - 7696 bytes