ComboFix 09-04-27.02 - B 04/27/2009 22:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.3070.2526 [GMT 3:00]
Running from: c:\documents and settings\B\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\kakle.dll
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
c:\windows\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-27 to 2009-4-27 )))))))))))))))))))))))))))))))
.
2009-04-27 12:16 . 2009-04-27 12:16 -------- d-----w C:\DriveKey
2009-04-27 00:00 . 2009-04-27 00:06 -------- d-----w c:\documents and settings\B\Local Settings\Application Data\AskToolbar
2009-04-26 22:15 . 2009-04-27 10:34 -------- d-----w c:\program files\Ask.com
2009-04-26 22:14 . 2009-04-26 22:14 -------- d-----w c:\program files\FormatFactory
2009-04-26 21:48 . 2009-04-26 21:49 -------- d-----w c:\program files\NoLimits Demo v1.262
2009-04-26 13:19 . 2009-04-26 13:19 -------- d-----w c:\program files\GameTop.com
2009-04-26 13:15 . 2009-04-26 13:15 -------- d-----w c:\documents and settings\B\Application Data\Ashampoo
2009-04-26 13:15 . 2009-04-26 13:15 -------- d-----w c:\documents and settings\B\Local Settings\Application Data\ashampoo
2009-04-26 13:15 . 2009-04-26 13:15 -------- d-----w c:\documents and settings\All Users\Application Data\ashampoo
2009-04-26 13:14 . 2009-04-26 13:14 -------- d-----w c:\program files\Ashampoo
2009-04-26 10:38 . 2009-04-26 10:38 -------- d-----w c:\program files\UberIcon
2009-04-25 23:29 . 2009-04-25 23:36 -------- d-----w c:\documents and settings\B\Application Data\ooVoo Details
2009-04-25 23:29 . 2009-04-25 23:29 -------- d-----w c:\documents and settings\B\Application Data\Thinstall
2009-04-25 23:29 . 2009-04-25 23:29 -------- d-----w c:\documents and settings\B\Local Settings\Application Data\Thinstall
2009-04-25 22:57 . 2009-04-25 23:12 -------- d-----w c:\documents and settings\B\DoctorWeb
2009-04-25 21:00 . 2009-04-25 21:00 -------- d-s---w c:\documents and settings\B\UserData
2009-04-25 19:09 . 2009-04-25 19:09 -------- d-----w c:\documents and settings\All Users\Application Data\TechSmith
2009-04-25 19:09 . 2009-04-25 19:09 -------- d-----w c:\documents and settings\B\Local Settings\Application Data\TechSmith
2009-04-25 19:07 . 2009-04-25 19:07 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-25 16:55 . 2009-04-25 16:55 -------- d-----w c:\windows\Ela-Salaty
2009-04-25 16:55 . 2009-04-25 16:59 -------- d-----w c:\program files\Ela-Salaty
2009-04-22 12:46 . 2009-04-22 12:46 -------- d-----w c:\windows\system32\RMBin
2009-04-22 12:46 . 2009-04-22 12:46 -------- d-----w c:\program files\Ozone
2009-04-21 19:07 . 2005-05-19 06:52 1212416 ----a-w c:\windows\system32\NCTAudioInformation2.dll
2009-04-21 19:07 . 2005-05-18 07:37 1986560 ----a-w c:\windows\system32\NCTAudioFile2.dll
2009-04-21 19:07 . 2007-10-12 13:09 1164728 ----a-w c:\windows\system32\NMSDVDXU.dll
2009-04-21 19:07 . 2005-09-23 18:48 1171456 ----a-w c:\windows\system32\msvcr80d.dll
2009-04-21 19:07 . 2007-10-09 20:06 626688 ----a-w c:\windows\system32\msvcr80.dll
2009-04-21 19:07 . 2009-04-21 19:07 -------- d-----w c:\program files\CD Copy Master
2009-04-16 00:30 . 2009-04-16 00:30 -------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
2009-04-16 00:27 . 2009-04-16 00:27 -------- d-----w c:\program files\Bonjour
2009-04-16 00:21 . 2009-04-16 00:21 -------- d-----w c:\program files\Common Files\Macrovision Shared
2009-04-15 18:05 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-27 19:11 . 2009-01-28 13:20 2412064 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-27 19:11 . 2009-01-28 13:20 20972 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-27 19:11 . 2009-01-28 13:20 540704 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-27 19:11 . 2009-01-28 13:20 3976 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-27 12:16 . 2009-01-27 18:40 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-22 12:47 . 2009-04-22 12:47 98304 ----a-w c:\windows\system32\viscomtran.dll
2009-04-22 12:42 . 2009-02-04 20:57 -------- d-----w c:\program files\MPlayer for Windows
2009-04-19 14:12 . 2009-04-19 14:12 172 ----a-w C:\curr_ver.tmp
2009-04-16 00:42 . 2009-02-10 08:24 77504 ----a-w c:\documents and settings\B\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-16 00:27 . 2009-01-27 20:27 -------- d-----w c:\program files\Common Files\Adobe
2009-03-20 18:32 . 2009-03-20 18:31 -------- d-----w c:\program files\Common Files\delet
2009-03-17 16:46 . 2009-03-17 16:46 -------- d-----w c:\program files\XP TCPIP Repair
2009-03-16 08:48 . 2009-03-16 08:48 -------- d-----w c:\program files\NewEESS
2009-03-15 11:00 . 2009-03-15 11:00 -------- d-----w c:\program files\Wireless WEP Key Password Spy
2009-03-13 00:18 . 2009-03-13 00:18 -------- d-----w c:\program files\TeamViewer
2009-03-09 05:14 . 2009-03-09 05:14 -------- d-----w c:\program files\Ashalshaikh
2009-03-08 20:20 . 2009-03-08 20:20 -------- d-----w c:\program files\Common Files\Nero
2009-03-08 20:20 . 2009-03-08 20:19 -------- d-----w c:\program files\Nero
2009-03-08 19:48 . 2009-03-08 19:48 -------- d-----w c:\program files\Cryptomathic
2009-03-08 08:02 . 2009-01-27 20:49 -------- d-----w c:\program files\The KMPlayer
2009-03-07 19:18 . 2009-03-07 19:18 2188 ----a-w c:\windows\system32\50001T.dll
2009-03-06 15:31 . 2009-03-06 15:31 -------- d-----w c:\program files\Universal Viewer
2009-03-06 14:22 . 2008-04-14 02:42 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-04 11:40 . 2009-03-04 11:39 -------- d-----w c:\program files\UltraISO
2009-03-04 11:39 . 2009-03-04 11:39 -------- d-----w c:\program files\Common Files\EZB Systems
2009-03-04 07:18 . 2009-03-04 07:18 -------- d-----w c:\program files\Elmokadim Flash Player
2009-03-01 09:45 . 2009-03-01 09:37 -------- d-----w c:\program files\Google
2009-03-01 09:07 . 2009-03-01 09:07 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-01 09:07 . 2009-01-27 15:32 -------- d-----w c:\program files\Java
2009-02-26 11:58 . 2009-02-26 11:51 720896 ----a-w c:\windows\iun6002ev.exe
2009-02-22 01:05 . 2009-02-22 01:05 286720 ------w c:\windows\Setup1.exe
2009-02-22 01:05 . 2009-02-22 01:05 73216 ----a-w c:\windows\ST6UNST.EXE
2009-02-20 08:10 . 2008-04-14 02:42 666112 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2008-04-14 02:41 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-16 12:56 . 2009-02-16 03:03 245992 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-02-10 11:43 . 2008-01-29 14:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-09 12:10 . 2008-04-14 02:41 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2008-04-14 02:42 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2008-04-14 02:41 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2008-04-14 02:41 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 11:13 . 2008-04-13 22:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2008-04-14 02:42 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2008-04-13 21:54 2145280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2001-08-23 12:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2008-04-14 00:01 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-04 19:17 . 2009-01-28 13:21 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-04 19:17 . 2009-01-28 13:21 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-02-03 19:59 . 2008-04-14 02:42 56832 ----a-w c:\windows\system32\secur32.dll
2009-01-27 19:52 . 2009-01-27 19:52 503808 ----a-w c:\windows\system32\aawsat_clock.scr
2009-01-27 19:52 . 2009-01-27 19:52 12288 ----a-w c:\windows\system32\impborl.dll
.
------- Sigcheck -------
[-] 2008-11-05 12:41 1614848 5504EFF23CE88A875C98B4C55487FF1D c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-01-27 2745776]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"UberIcon"="c:\program files\UberIcon\UberIcon Manager.exe" [2007-08-17 159744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-01 136600]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2008-05-27 360448]
"Toshiba Hotkey Utility"="c:\program files\Toshiba\Windows Utilities\Hotkey.exe" [2008-05-09 1773568]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2008-04-29 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"pdfFactory Pro Dispatcher v3"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2008-10-27 573440]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-27 185896]
"StormCodec_Helper"="c:\program files\Ringz Studio\Storm Codec\StormSet.exe" [2006-11-26 97357]
"QuickTime Task"="c:\program files\Ringz Studio\Storm Codec\QTTask.exe" [2008-05-27 413696]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-10 206088]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-11-06 16384512]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
"TFncKy"="TFncKy.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2008-04-14 99840]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2008-04-14 99840]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Monitor.lnk - c:\program files\TOSHIBA\Bluetooth Monitor\BtMon2.exe [2009-1-27 92280]
Snagit 9.lnk - c:\program files\TechSmith\SnagIt 9\Snagit32.exe [2009-4-17 7226184]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-2-8 394856]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegedit"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-02-10 33808]
S0 ulsata2;ulsata2; [x]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2007-04-04 5888]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
S3 QIOMem;Generic IO & Memory Access;c:\windows\system32\DRIVERS\QIOMem.sys [2007-05-29 6912]
.
Contents of the 'Scheduled Tasks' folder
2009-03-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 14:57]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-MouseLight - \MouseLight.exe
HKLM-Run-Device Detector - DevDetect.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Connection Wizard,ShellNext = hxxp://www.internetdownloadmanager.com/welcome.html
uInternet Settings,ProxyOverride = *.local
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: إفحص باستخدام د. وب -
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-27 22:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):6a,5f,f1,64,82,10,47,9a,d5,ef,0d,13,08,ea,a5,62,dc,92,8b,6b,9a,
85,ea,00,2f,fd,34,2c,70,bb,1c,7d,fe,01,88,35,63,2f,19,47,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8295ae3f-a724-4d18-8ad1-0275ffc9e520}]
@Denied: (Full) (Everyone)
"Model"=dword:00000068
"Therad"=dword:00000001
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,ae,ee,22,f6,7f,
32,e6,14,05,98,32,02,34,2b,da,61,5a,24,8c,1a,de,d6,a3,f7,fd,8a,da,ba,c4,57,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1068)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(236)
c:\program files\UberIcon\UberIcon.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\ACD Systems\EN\DevDetect.exe
c:\program files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
c:\program files\TechSmith\SnagIt 9\TscHelp.exe
c:\program files\TechSmith\SnagIt 9\SnagPriv.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe
c:\program files\TechSmith\SnagIt 9\SnagitEditor.exe
c:\program files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-27 22:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-27 19:13
Pre-Run: 92,870,402,048 bytes free
Post-Run: 93,122,945,024 bytes free
240 --- E O F --- 2009-04-16 00:01
وهذا تقرير الهايجاك بعد فحص أداة ComboFix
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:19:20 م, on 27/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\TechSmith\SnagIt 9\Snagit32.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\TechSmith\SnagIt 9\TSCHelp.exe
C:\Program Files\TechSmith\SnagIt 9\SnagPriv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TechSmith\SnagIt 9\snagiteditor.exe
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\B\Desktop\Zyzoom_HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v3] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" /source=HKLM
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\Ringz Studio\Storm Codec\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Bluetooth Monitor.lnk = ?
O4 - Global Startup: Snagit 9.lnk = C:\Program Files\TechSmith\SnagIt 9\Snagit32.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: إفحص باستخدام د. وب -
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) -
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
--
End of file - 9078 bytes
أما أداة الكاسبر فلم أستطع تحميلها نظراً لحجمها