هذا هو التقرير لـــ combofix
ComboFix 09-04-04.01 - Sasi 2009-04-11 5:44:09.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.965.1033.18.3071.2510 [GMT 3:00]
Running from: d:\show\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
AV: Rising Antivirus *On-access scanning enabled* (Outdated)
FW: Kaspersky Internet Security *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
c:\windows\ksires32.dll
c:\windows\msxfcg32.dll
c:\windows\system32\Plugins
c:\windows\system32\Plugins\ml\ml_pmp_device_Shakoosh - Phone memory.ini
.
((((((((((((((((((((((((( Files Created from 2009-03-11 to 2009-04-11 )))))))))))))))))))))))))))))))
.
2009-11-08 08:31 . 2009-11-08 08:31 <DIR> d-------- c:\program files\Torrent Harvester
2009-11-07 07:58 . 2009-11-07 07:58 <DIR> d-------- c:\windows\system32\Codec
2009-11-07 07:58 . 2009-11-07 07:58 <DIR> d-------- C:\Video Center
2009-04-11 05:41 . 2006-03-02 23:42 73,728 --a------ C:\pv.exe
2009-04-08 07:45 . 2009-04-08 07:45 <DIR> d-------- c:\program files\Dachshund Software
2009-04-08 07:45 . 2009-04-08 07:46 72 --ah----- c:\windows\winshell.dat
2009-04-06 09:52 . 2009-04-06 09:52 <DIR> d-------- c:\program files\IE Accelerator
2009-04-06 08:38 . 2009-04-06 08:38 <DIR> d-------- c:\program files\Windows Defender
2009-04-05 07:48 . 2009-04-05 08:18 <DIR> d-------- c:\program files\ProgDVB
2009-04-05 05:00 . 2009-04-05 05:00 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2009-04-05 05:00 . 2009-04-05 05:00 <DIR> d-------- c:\program files\Common Files\Intel
2009-04-05 05:00 . 2009-04-05 05:00 <DIR> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2009-04-04 09:39 . 2009-04-05 08:58 <DIR> d-------- c:\program files\RenQuranFiles
2009-04-04 09:39 . 2000-01-24 05:01 2,023,424 --a------ c:\windows\system32\VCL50.BPL
2009-04-04 09:39 . 1999-03-23 09:12 299,520 --a------ c:\windows\uninst.exe
2009-04-02 09:54 . 2007-11-30 17:31 26,112 --a------ c:\windows\system32\drivers\usbser.sys
2009-04-02 09:54 . 2007-11-30 17:31 26,112 --a--c--- c:\windows\system32\dllcache\usbser.sys
2009-04-02 09:53 . 2008-03-21 13:57 14,640 --------- c:\windows\system32\spmsgXP_2k3.dll
2009-04-02 09:53 . 2009-04-02 09:53 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-04-02 09:53 . 2009-04-02 09:53 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-04-02 07:16 . 2009-04-11 05:48 6,006,816 --a------ c:\windows\system32\drivers\fidbox.dat
2009-04-02 07:16 . 2009-04-11 05:48 557,088 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2009-04-02 07:16 . 2009-04-11 05:48 49,056 --ahs---- c:\windows\system32\drivers\fidbox.idx
2009-04-02 07:16 . 2009-04-11 05:48 4,032 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2009-04-02 07:08 . 2009-04-02 07:09 <DIR> d-------- c:\program files\XP TCPIP Repair
2009-03-31 05:33 . 2009-04-01 04:39 32 --a------ c:\windows\
0
2009-03-31 05:33 . 2009-03-31 05:33 0 --a------ c:\windows\system32\
0
2009-03-30 09:41 . 2006-08-10 15:16 2,435,613 --a------ c:\windows\system32\Avc.ax
2009-03-30 09:41 . 2005-01-19 18:23 25,600 --a------ c:\windows\system32\AVSredirect.dll
2009-03-30 06:44 . 2009-03-30 06:44 34 --ah----- c:\windows\system32\MP3ToAMRConverter_sysquict.dat
2009-03-30 06:43 . 2009-03-30 07:59 <DIR> d-------- c:\program files\Okoker MP3 To AMR Converter
2009-03-30 06:31 . 2009-03-30 06:31 <DIR> d-------- c:\program files\7-Zip
2009-03-24 17:27 . 2009-03-24 17:30 <DIR> d-------- C:\KidsMath
2009-03-24 17:27 . 2004-04-15 18:23 347,136 --a------ c:\windows\system32\FM20.oca
2009-03-24 17:27 . 2001-01-17 07:01 260,096 --a------ c:\windows\system32\RICHTX32.OCX
2009-03-24 17:27 . 2000-05-22 16:58 115,920 --a------ c:\windows\system32\MSINET.OCX
2009-03-24 17:27 . 1998-04-24 00:00 83,552 --a------ c:\windows\system32\GAPI32.DLL
2009-03-24 17:27 . 2004-08-25 22:53 62,464 --a------ c:\windows\system32\MCI32.oca
2009-03-24 17:27 . 1998-04-24 00:00 30,720 --a------ c:\windows\system32\RCHTXCHS.DLL
2009-03-24 17:27 . 2001-02-01 23:40 26,384 --a------ c:\windows\system32\FM20CHS.DLL
2009-03-24 17:27 . 1998-07-07 00:00 13,824 --a------ c:\windows\system32\INETCHS.DLL
2009-03-24 17:27 . 1998-06-18 00:00 2,396 --a------ c:\windows\system32\MCI32.DEP
2009-03-23 09:12 . 2009-03-23 09:19 <DIR> d-------- c:\windows\Backups
2009-03-23 09:12 . 2009-03-23 09:12 <DIR> d-------- c:\windows\AutoREGs
2009-03-23 09:11 . 2009-03-23 09:18 404,319 --a------ c:\windows\zakrpa.exe
2009-03-23 09:11 . 2009-03-23 09:18 60 --a------ c:\windows\automatski.cmd
2009-03-20 08:53 . 2009-03-20 08:53 <DIR> d-------- c:\program files\Common Files\xing shared
2009-03-20 07:46 . 2009-03-20 07:46 397 --a------ C:\home.htm
2009-03-19 11:55 . 2009-03-19 11:55 <DIR> d-------- c:\documents and settings\Sasi\Application Data\ACD Systems
2009-03-16 11:09 . 2009-03-16 12:01 (2) -rahs-ot- c:\windows\winstart.bat
2009-03-16 08:48 . 2009-03-16 08:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Drivers Headquarters
2009-03-16 08:38 . 2009-03-16 09:59 <DIR> d-------- c:\program files\PC Drivers HeadQuarters
2009-03-16 06:34 . 2009-03-16 06:34 <DIR> d-------- c:\documents and settings\Sasi\Application Data\COWON
2009-03-16 06:33 . 2009-03-16 10:06 <DIR> d-------- c:\program files\JetAudio
2009-03-16 06:33 . 2009-03-16 06:33 <DIR> d-------- c:\program files\Common Files\COWON
2009-03-13 08:54 . 2009-03-29 10:13 <DIR> d-------- c:\documents and settings\Sasi\Application Data\AIMP
2009-03-13 08:53 . 2009-03-13 10:44 <DIR> d-------- c:\program files\AIMP2
2009-03-11 10:58 . 2009-03-11 10:58 <DIR> d-------- c:\program files\DatawareGames
2009-03-11 07:59 . 2009-03-11 07:59 <DIR> d-------- c:\windows\Downloaded Installations
2009-03-11 07:59 . 2009-03-11 08:00 <DIR> d-------- c:\program files\Bluetooth Remote Control
2009-03-11 06:42 . 2009-03-11 06:49 <DIR> d-------- c:\program files\Photo To Color Sketch
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-11 02:58 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-11 02:39 --------- d-----w c:\documents and settings\Sasi\Application Data\GetRight Pro
2009-04-08 05:59 --------- d-----w c:\documents and settings\Sasi\Application Data\X-NetStat
2009-04-05 02:01 --------- d-----w c:\program files\Intel
2009-04-02 06:19 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-04-02 06:19 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-04-02 06:19 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-04-01 16:38 --------- d-----w c:\program files\File Renamer Turbo
2009-04-01 16:37 --------- d-----w c:\program files\Any Audio Converter
2009-04-01 16:36 --------- d-----w c:\program files\Cooolsoft
2009-04-01 15:14 --------- d-----w c:\program files\Ivacy Monitor
2009-03-29 06:16 --------- d-----w c:\program files\MP3 Workshop
2009-03-24 14:30 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-24 14:30 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-23 06:08 --------- d-----w c:\program files\Common Files\Elecard
2009-03-20 11:51 --------- d-----w c:\documents and settings\Sasi\Application Data\PC Suite
2009-03-20 05:53 --------- d-----w c:\program files\Common Files\Real
2009-03-20 05:23 --------- d-----w c:\program files\vSoft
2009-03-17 02:10 --------- d-----w c:\documents and settings\Sasi\Application Data\Picofactory
2009-03-17 02:10 --------- d-----w c:\documents and settings\Sasi\Application Data\Paltalk
2009-03-17 02:10 --------- d-----w c:\documents and settings\Sasi\Application Data\Nokia
2009-03-17 02:09 --------- d-----w c:\documents and settings\Sasi\Application Data\SlipStream
2009-03-17 01:58 --------- d-----w c:\program files\IE Doctor
2009-03-08 08:24 --------- d-----w c:\program files\QuickTime
2009-03-08 08:24 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-07 09:02 --------- d-----w c:\program files\Essentials Codec Pack
2009-03-07 05:39 --------- d-----w c:\program files\intocartoonpro
2009-03-05 08:30 --------- d-----w c:\program files\X-NetStat Professional
2009-03-05 06:33 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-03 14:24 --------- d--h--w c:\program files\InstallJammer Registry
2009-03-02 06:03 --------- d-----w c:\program files\SkyGrabber
2009-03-01 13:52 --------- d-----w c:\program files\Common Files\DFX
2009-03-01 12:21 --------- d-----w c:\program files\Real
2009-03-01 05:42 --------- d-----w c:\program files\FDRLab
2009-02-28 08:51 --------- d-----w c:\program files\K-Lite Codec Pack
2009-02-28 07:35 --------- d-----w c:\documents and settings\All Users\Application Data\DFX
2009-02-26 09:16 121,856 ----a-w c:\windows\system32\drivers\Rtenicxp.sys
2009-02-26 05:52 --------- d-----w c:\program files\Streambox
2009-02-21 08:39 --------- d-----w c:\documents and settings\Sasi\Application Data\Image Zone Express
2009-02-21 08:38 --------- d-----w c:\program files\VistaCodecPack
2009-02-21 08:35 --------- d-----w c:\documents and settings\All Users\Application Data\Win7codecs
2009-02-21 07:10 --------- d-----w c:\program files\Common Files\ACD Systems
2009-02-21 07:10 --------- d-----w c:\documents and settings\All Users\Application Data\ACD Systems
2009-02-21 07:09 --------- d-----w c:\program files\ACD Systems
2009-02-21 06:24 --------- d-----w c:\documents and settings\Sasi\Application Data\Mp3tag
2009-02-21 06:17 --------- d-----w c:\program files\Mp3tag
2009-02-20 18:26 --------- d-----w c:\documents and settings\All Users\Application Data\SRSLabs
2009-02-20 07:30 --------- d-----w c:\program files\SRSLabs
2009-02-20 07:30 --------- d-----w c:\program files\Common Files\SRS
2009-02-20 07:25 --------- d-----w c:\program files\Appwalk.com Technologies Canada
2009-02-20 06:24 --------- d-----w c:\documents and settings\Sasi\Application Data\Kristanix Software
2009-02-20 03:32 --------- d-----w c:\program files\Apple Software Update
2009-02-19 06:51 --------- d-----w c:\program files\Video Convert Master
2009-02-17 18:18 --------- d-----w c:\program files\GetRight
2009-02-17 08:01 --------- d-----w c:\program files\McFunSoft Audio Converter
2009-02-16 17:10 --------- d-----w c:\documents and settings\Sasi\Application Data\Nokia Multimedia Player
2009-02-16 05:59 --------- d-----w c:\program files\Nokia
2009-02-16 05:59 --------- d-----w c:\program files\Common Files\PCSuite
2009-02-16 05:59 --------- d-----w c:\program files\Common Files\Nokia
2009-02-12 23:15 45,056 ----a-w c:\windows\NCUNINST.EXE
2009-02-12 23:13 --------- d-----w c:\program files\Common Files\SWF Studio
2009-02-12 22:56 --------- d-----w c:\documents and settings\Sasi\Application Data\EbkReader
2009-02-12 15:26 --------- d-----w c:\program files\HP
2009-02-12 15:26 --------- d-----w c:\program files\Common Files\HP
2009-02-12 15:25 --------- d-----w c:\documents and settings\All Users\Application Data\HPSSUPPLY
2009-02-11 19:02 --------- d-----w c:\program files\PC Connectivity Solution
2009-02-11 19:00 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2007-12-01 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-04 206088]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-20 198160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2007-12-01 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ToggleCommentPosition"= 1 (0x1)
"PreXPSP2ShellProtocolBehavior"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bilal Prayer.LNK]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bilal Prayer.LNK
backup=c:\windows\pss\Bilal Prayer.LNKCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ONSPEED.lnk]
backup=c:\windows\pss\ONSPEED.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Server4PC.lnk]
backup=c:\windows\pss\Server4PC.lnkCommon Startup
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Server4PC.lnk
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Sasi^Start Menu^Programs^Startup^AntiCrash.lnk]
path=c:\documents and settings\Sasi\Start Menu\Programs\Startup\AntiCrash.lnk
backup=c:\windows\pss\AntiCrash.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Sasi^Start Menu^Programs^Startup^BitTorrent SpeedUp Pro.lnk]
path=c:\documents and settings\Sasi\Start Menu\Programs\Startup\BitTorrent SpeedUp Pro.lnk
backup=c:\windows\pss\BitTorrent SpeedUp Pro.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdVantage Setup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IE Doctor
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-11 10:06 40048 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLD.EXE]
--a------ 2007-09-17 00:16 1343488 c:\program files\Download Direct\DLD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 07:00 33648 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-05-08 16:24 54840 c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2007-12-01 00:26 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-09-01 15:57 282624 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--------- 2009-03-20 08:52 198160 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USB Antivirus]
--a------ 2008-12-18 11:37 798720 c:\program files\USB Disk Security\USBGuard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2006-11-03 19:20 866584 c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2008-06-19 16:20 57344 c:\windows\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
--a------ 2008-06-19 16:42 2808832 c:\windows\ALCWZRD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-09-17 23:55 1657376 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2008-12-30 14:58 18082304 c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
--a------ 2007-11-20 18:15 1826816 c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2008-08-19 13:26 77824 c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\drivers\SkyNET.sys [2008-06-18 451816]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b956fbc4-bfab-11dd-97b1-00d0d70a46fe}]
\Shell\AutoRun\command - sq.com
\Shell\explore\Command - sq.com
\Shell\open\Command - sq.com
.
Contents of the 'Scheduled Tasks' folder
2009-04-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 14:21]
2009-04-11 c:\windows\Tasks\WECPUpdate.job
- c:\program files\Essentials Codec Pack\WECPUpdate.exe [2009-02-25 17:28]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Eraser RiskMonitor - c:\program files\East-Tec Eraser 2009\Launch.exe
MSConfigStartUp-Malwarebytes' Anti-Malware - c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
MSConfigStartUp-MMTray - c:\program files\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\MMTray.exe
MSConfigStartUp-mmtray2k - c:\program files\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtray2k.exe
MSConfigStartUp-mmtraylsi - c:\program files\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtraylsi.exe
MSConfigStartUp-PC Suite Tray - c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
MSConfigStartUp-rfagent - c:\program files\RFA\rfagent.exe
MSConfigStartUp-SlipStream - c:\program files\ONSPEED\onspeedcore.exe
MSConfigStartUp-WinampAgent - c:\program files\Winamp\winampa.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = about:blank
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyServer = 189.72.74.4:31280
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: Download with GetRight Pro - c:\program files\GetRight\GRdownload.htm
IE: Open with GetRight Pro Browser - c:\program files\GetRight\GRbrowse.htm
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-11 06:01:06
Windows 5.1.2600 Service Pack 3, v.5657 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-842925246-1979792683-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{83732A8B-CD31-B96B-5A44-A33A8B8E11C7}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"fanpllghjdmb"=hex:6f,62,6a,6f,6d,6c,6e,62,64,63,63,64,64,61,64,63,6e,68,65,70,
62,63,6c,65,6d,66,69,61,69,6a,6b,6a,64,70,61,68,6a,61,6c,63,6d,65,6f,6b,6a,\
"gaefedoigihmba"=hex:61,62,6b,6f,70,6c,64,62,63,6c,61,64,6f,62,63,65,68,66,68,
69,6f,63,64,70,6d,70,6b,6b,66,6d,6e,6e,69,69,00,7e
"gannbdnbkbmfij"=hex:65,62,6d,6f,66,6a,64,66,63,6e,68,6d,69,70,67,6d,64,65,6e,
61,6b,70,6c,68,6b,6a,6d,6f,70,6a,68,6f,63,6b,6a,67,70,62,6c,6b,65,68,00,00
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\searchindexer.exe
c:\program files\Canon\CAL\CALMAIN.exe
.
**************************************************************************
.
Completion time: 2009-04-11 6:05:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-11 03:05:45
Pre-Run: 123,239,735,296 bytes free
Post-Run: 123,883,864,064 bytes free
323