عطل جميع برامج الحماية ,,
وحمل هذه الاداة واحفظها على سطح المكتب
عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
انتظر حتى الاداة تنتهي من فحص جهازك ,,, وبشكل تلقائي يعاد تشغيل جهازك ,,
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
انتظر حتى يظهر لك تقرير ,, انسخه والصقه بردك القادم
ComboFix 09-04-15.08 - mohsen sharaf 04/15/2009 16:55.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.20.1033.18.1015.510 [GMT 2:00]
Running from: c:\documents and settings\mohsen sharaf\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-03-15 to 2009-04-15 )))))))))))))))))))))))))))))))
.
2009-04-15 14:09 . 2009-04-15 14:09 -------- d-sh--w C:\FOUND.000
2009-04-15 00:57 . 1999-12-17 08:13 86016 ----a-w c:\windows\unvise32.exe
2009-04-15 00:19 . 2009-04-15 00:19 -------- d--h--w C:\SmartSound Software
2009-04-15 00:19 . 2009-04-15 00:19 -------- d-----w c:\documents and settings\All Users\Application Data\SmartSound Software Inc
2009-04-07 17:42 . 2009-04-07 17:42 -------- d-----w c:\documents and settings\mohsen sharaf\Application Data\Paltalk
2009-04-02 20:58 . 2009-04-02 20:58 -------- d-----w c:\windows\SHELLNEW
2009-04-02 05:03 . 2009-04-02 05:03 -------- d-----w c:\documents and settings\LocalService\Application Data\SACore
2009-04-02 05:02 . 2009-04-02 05:02 -------- d-----w c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-04-02 05:00 . 2009-04-02 05:00 -------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2009-03-28 14:43 . 2009-03-28 14:43 -------- d-----w c:\documents and settings\mohsen sharaf\Local Settings\Application Data\WMTools Downloaded Files
2009-03-23 13:49 . 2009-03-23 13:49 -------- d-sh--w c:\documents and settings\mohsen sharaf\IECompatCache
2009-03-23 09:21 . 2009-03-23 09:21 -------- d-sh--w c:\documents and settings\mohsen sharaf\PrivacIE
2009-03-23 08:35 . 2009-03-23 08:35 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-03-23 08:35 . 2009-03-23 08:35 -------- d-sh--w c:\documents and settings\mohsen sharaf\IETldCache
2009-03-23 07:01 . 2009-03-23 07:01 -------- d-----w c:\windows\ie8updates
2009-03-23 06:52 . 2009-03-23 06:52 -------- d--h--w c:\windows\ie8
2009-03-23 06:46 . 2009-02-28 04:55 105984 ------w c:\windows\system32\dllcache\iecompat.dll
2009-03-22 19:06 . 2009-03-22 19:06 -------- d-----w c:\documents and settings\mohsen sharaf\Application Data\FlashFXP
2009-03-20 20:06 . 2000-06-26 20:52 266293 ----a-w c:\windows\system\MSVCRT.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-15 14:59 . 2008-09-04 19:29 32 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-15 14:59 . 2008-09-04 19:29 32 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-15 14:59 . 2008-09-04 19:29 32 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-15 14:59 . 2008-09-04 19:29 32 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-15 14:59 . 2008-09-04 19:29 32 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-15 14:59 . 2008-09-04 19:29 32 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-15 01:55 . 2009-04-15 01:55 -------- d-----w c:\program files\Common Files\Canopus Shared
2009-04-15 01:55 . 2009-04-15 01:55 -------- d-----w c:\program files\Canopus
2009-04-15 00:52 . 2009-04-15 00:52 -------- d-----w c:\program files\Pinnacle
2009-04-15 00:19 . 2009-04-15 00:19 -------- d-----w c:\program files\SmartSound Software
2009-04-14 14:15 . 2009-04-14 14:15 -------- d-----w c:\program files\Corel
2009-04-10 20:02 . 2009-04-10 20:02 -------- d-----w c:\program files\MyPlayCity.com
2009-04-03 21:35 . 2008-09-04 19:22 1020144 ----a-w c:\documents and settings\mohsen sharaf\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-02 21:14 . 2009-04-02 21:14 -------- d-----w c:\program files\Microsoft ActiveSync
2009-04-02 05:02 . 2009-04-02 05:02 -------- d-----w c:\program files\Common Files\McAfee
2009-04-02 00:45 . 2009-04-02 00:45 -------- d-----w c:\program files\MSN Messenger
2009-04-01 18:45 . 2009-04-01 18:45 -------- d-----w c:\program files\Microsoft
2009-03-08 12:09 . 2008-09-04 17:55 638816 ----a-w c:\windows\system32\dllcache\iexplore.exe
2009-03-08 12:09 . 2008-04-14 10:00 391536 ----a-w c:\windows\system32\dllcache\iedkcs32.dll
2009-03-08 02:41 . 2008-04-14 10:00 5937152 ----a-w c:\windows\system32\dllcache\mshtml.dll
2009-03-08 02:34 . 2008-04-14 13:00 914944 ----a-w c:\windows\system32\dllcache\wininet.dll
2009-03-08 02:34 . 2008-04-14 10:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 02:34 . 2008-04-14 13:00 1206784 ----a-w c:\windows\system32\dllcache\urlmon.dll
2009-03-08 02:34 . 2008-04-14 10:00 236544 ----a-w c:\windows\system32\dllcache\webcheck.dll
2009-03-08 02:34 . 2008-04-14 10:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 02:34 . 2008-04-14 10:00 43008 ----a-w c:\windows\system32\dllcache\licmgr10.dll
2009-03-08 02:34 . 2008-04-14 13:00 105984 ----a-w c:\windows\system32\dllcache\url.dll
2009-03-08 02:34 . 2008-04-14 10:00 193536 ----a-w c:\windows\system32\dllcache\msrating.dll
2009-03-08 02:34 . 2008-04-14 10:00 109568 ----a-w c:\windows\system32\dllcache\occache.dll
2009-03-08 02:33 . 2008-09-04 17:56 759296 ----a-w c:\windows\system32\dllcache\VGX.dll
2009-03-08 02:33 . 2008-04-14 10:00 18944 ----a-w c:\windows\system32\dllcache\corpol.dll
2009-03-08 02:33 . 2008-04-14 10:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 02:33 . 2008-04-14 10:00 25600 ----a-w c:\windows\system32\dllcache\jsproxy.dll
2009-03-08 02:33 . 2008-04-14 10:00 726528 ----a-w c:\windows\system32\dllcache\jscript.dll
2009-03-08 02:33 . 2008-04-14 10:00 229376 ----a-w c:\windows\system32\dllcache\ieaksie.dll
2009-03-08 02:33 . 2008-04-14 10:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 02:33 . 2008-04-14 10:00 420352 ----a-w c:\windows\system32\dllcache\vbscript.dll
2009-03-08 02:33 . 2008-04-14 10:00 125952 ----a-w c:\windows\system32\dllcache\ieakeng.dll
2009-03-08 02:32 . 2008-04-14 10:00 72704 ----a-w c:\windows\system32\dllcache\admparse.dll
2009-03-08 02:32 . 2008-04-14 10:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 02:32 . 2008-04-14 10:00 173056 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2009-03-08 02:32 . 2008-04-14 10:00 163840 ----a-w c:\windows\system32\dllcache\ieakui.dll
2009-03-08 02:32 . 2008-04-14 10:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 02:32 . 2008-04-14 10:00 71680 ----a-w c:\windows\system32\dllcache\iesetup.dll
2009-03-08 02:32 . 2008-04-14 10:00 55808 ----a-w c:\windows\system32\dllcache\iernonce.dll
2009-03-08 02:32 . 2008-04-14 13:00 128512 ----a-w c:\windows\system32\dllcache\advpack.dll
2009-03-08 02:32 . 2008-04-14 10:00 94720 ----a-w c:\windows\system32\dllcache\inseng.dll
2009-03-08 02:32 . 2008-04-14 10:00 611840 ----a-w c:\windows\system32\dllcache\mstime.dll
2009-03-08 02:31 . 2008-04-14 10:00 183808 ----a-w c:\windows\system32\dllcache\iepeers.dll
2009-03-08 02:31 . 2008-04-14 10:00 348160 ----a-w c:\windows\system32\dllcache\dxtmsft.dll
2009-03-08 02:31 . 2008-04-14 10:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 02:31 . 2008-04-14 10:00 34816 ----a-w c:\windows\system32\dllcache\imgutil.dll
2009-03-08 02:31 . 2008-04-14 10:00 216064 ----a-w c:\windows\system32\dllcache\dxtrans.dll
2009-03-08 02:31 . 2008-04-14 10:00 46592 ----a-w c:\windows\system32\dllcache\pngfilt.dll
2009-03-08 02:31 . 2008-04-14 10:00 66560 ----a-w c:\windows\system32\dllcache\mshtmled.dll
2009-03-08 02:31 . 2008-04-14 10:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 02:31 . 2008-04-14 10:00 48128 ----a-w c:\windows\system32\dllcache\mshtmler.dll
2009-03-08 02:31 . 2008-04-14 10:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 02:31 . 2008-04-14 10:00 45568 ----a-w c:\windows\system32\dllcache\mshta.exe
2009-03-08 02:24 . 2008-09-04 17:55 68608 ----a-w c:\windows\system32\dllcache\hmmapi.dll
2009-03-08 02:22 . 2008-04-14 10:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-08 02:22 . 2008-04-14 10:00 156160 ----a-w c:\windows\system32\dllcache\msls31.dll
2009-02-28 22:28 . 2009-02-28 22:28 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-02-28 22:28 . 2009-02-28 22:28 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-02-28 22:24 . 2009-02-28 22:24 -------- d-----w c:\program files\PC Connectivity Solution
2009-02-27 08:58 . 2009-02-27 08:58 -------- d-----w c:\program files\SLD Codec Pack
2009-02-25 20:44 . 2009-02-25 20:44 -------- d-----w c:\documents and settings\mohsen sharaf\Application Data\Flock
2009-02-25 20:44 . 2009-02-25 20:44 -------- d-----w c:\program files\Flock
2009-02-21 05:10 . 2009-02-21 05:10 -------- d-----w c:\documents and settings\mohsen sharaf\Application Data\AdobeUM
2009-02-20 18:13 . 2009-02-20 18:13 -------- d-----w c:\program files\Common Files\Adobe
2009-02-15 22:46 . 2009-02-15 22:46 -------- d-----w c:\program files\LeapFTP
2009-01-19 17:08 . 2009-01-18 14:10 1004 --sha-w c:\windows\system32\sys_drv.dat
2008-10-23 01:30 . 2008-10-23 01:30 81920 ----a-w c:\documents and settings\mohsen sharaf\Application Data\ezpinst.exe
2008-10-23 01:30 . 2008-10-23 01:30 47360 ----a-w c:\documents and settings\mohsen sharaf\Application Data\pcouffin.sys
2008-03-09 05:25 . 2009-02-12 11:22 236 ---ha-w c:\program files\Common Files\dx.reg
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-06 206088]
"UVS12 Preload"="c:\program files\Corel\Corel VideoStudio 12\uvPL.exe" [2008-06-09 397456]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"VIDC.XFR1"= xfcodec.dll
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= c:\progra~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= c:\progra~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
backup=c:\windows\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VerbAce-Pro Startup Agent.lnk]
backup=c:\windows\pss\VerbAce-Pro Startup Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^mohsen sharaf^Start Menu^Programs^Startup^Ubisoft register.lnk]
backup=c:\windows\pss\Ubisoft register.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AntiARPStandalone
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 10:00 15360 ----a-w c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-11-28 06:52 77824 ----a-r c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-11-28 06:55 118784 ----a-r c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-11-28 06:55 98304 ----a-r c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-04-02 00:49 5674352 ----a-w c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-12-16 02:46 136600 ----a-w c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 11:43 69632 ------r c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-07-05 09:08 16380416 ------r c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2007-06-15 09:45 1826816 ------r c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R2 0265941239803575mcinstcleanup;0265941239803575mcinstcleanup; [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
R3 xAntiArp;xAntiArpSpoof Service; [x]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-02-06 33808]
S2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2008-12-17 603904]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-04-15 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 19:36]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Google Update - c:\documents and settings\mohsen sharaf\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
MSConfigStartUp-Nokia - c:\program files\Nokia\Nokia PC Suite 7\PCSync2.exe
MSConfigStartUp-PC Suite Tray - c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.eg/
mWindow Title = Microsoft Internet Explorer
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\mohsen sharaf\Application Data\Mozilla\Firefox\Profiles\49ajpu1f.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1392740&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - MyPlayCity Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1392740&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1392740&q=
FF - component: c:\documents and settings\mohsen sharaf\Application Data\Mozilla\Firefox\Profiles\49ajpu1f.default\extensions\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}\components\FFAlert.dll
FF - component: c:\documents and settings\mohsen sharaf\Application Data\Mozilla\Firefox\Profiles\49ajpu1f.default\extensions\mozilla_cc@internetdownloadmanager.com\components\idmmzcc.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
---- FIREFOX POLICIES ----
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-15 17:02
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):9a,d8,3d,ad,05,c7,2c,2e,d7,ec,1e,34,a3,03,50,a1,86,0d,e7,42,71,
60,a4,38,70,c2,e9,0e,75,56,c9,76,a5,cd,7b,7b,e3,f3,27,c7,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):7a,9f,a1,0c,b1,3a,48,ab,34,f3,e0,7d,51,f1,05,c8,d8,fa,64,cc,06,
77,ff,20,53,1f,83,b8,68,57,ce,15,64,7d,9e,14,18,9b,f7,7f,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7dd3c933-1542-4f27-b6d3-49024a1bac6d}]
@Denied: (Full) (Everyone)
"Model"=dword:0000000e
"Therad"=dword:00000015
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b3,72,29,d4,ba,
6b,bd,36,05,98,32,02,34,2b,da,61,f7,68,c4,a1,9c,99,f3,2a,56,4b,0f,6f,63,c6,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{df57f096-b61d-46f0-a6cb-75e14d87cb27}]
@Denied: (Full) (Everyone)
"Model"=dword:00000139
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3744)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2009-04-15 17:04 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-15 15:04
Pre-Run: 3,649,118,208 bytes free
Post-Run: 3,482,451,968 bytes free
263 --- E O F --- 2008-09-06 10:52